Chapter 22 VPN
VMG5313-B10A/-B30A Series User’s Guide
260
Transport Mode
Transport
mode is used to protect upper layer protocols and only affects the data in the IP packet.
In
Transport
mode, the IP packet contains the security protocol (
AH
or
ESP
) located after the
original IP header and options, but before any upper layer protocols contained in the packet (such
as TCP and UDP).
With
ESP,
protection is applied only to the upper layer protocols contained in the packet. The IP
header information and options are not used in the authentication process. Therefore, the
originating IP address cannot be verified for integrity against the data.
With the use of
AH
as the security protocol, protection is extended forward into the IP header to
verify the integrity of the entire packet by use of portions of the original IP header in the hashing
process.
Tunnel Mode
Tunnel
mode encapsulates the entire IP packet to transmit it securely. A
Tunnel
mode is required
for gateway services to provide access to internal systems.
Tunnel
mode is fundamentally an IP
tunnel with authentication and encryption. This is the most common mode of operation.
Tunnel
mode is required for gateway to gateway and host to gateway communications.
Tunnel
mode
communications have two sets of IP headers:
•
Outside header
: The outside IP header contains the destination IP address of the VPN gateway.
•
Inside header
: The inside IP header contains the destination IP address of the final system
behind the VPN gateway. The security protocol appears after the outer IP header and before the
inside IP header.
22.4.3 IKE Phases
There are two phases to every IKE (Internet Key Exchange) negotiation – phase 1 (Authentication)
and phase 2 (Key Exchange). A phase 1 exchange establishes an IKE SA and the second one uses
that SA to negotiate SAs for IPSec.
Содержание VMG5313-B10A
Страница 15: ...15 PART I User s Guide ...
Страница 16: ...16 ...
Страница 32: ...Chapter 2 The Web Configurator VMG5313 B10A B30A Series User s Guide 32 ...
Страница 40: ...Chapter 4 Tutorials VMG5313 B10A B30A Series User s Guide 40 ...
Страница 71: ...71 PART II Technical Reference ...
Страница 72: ...72 ...
Страница 78: ...Chapter 5 Network Map and Status Screens VMG5313 B10A B30A Series User s Guide 78 ...
Страница 106: ...Chapter 6 Broadband VMG5313 B10A B30A Series User s Guide 106 ...
Страница 162: ...Chapter 9 Routing VMG5313 B10A B30A Series User s Guide 162 ...
Страница 180: ...Chapter 10 Quality of Service QoS VMG5313 B10A B30A Series User s Guide 180 ...
Страница 198: ...Chapter 11 Network Address Translation NAT VMG5313 B10A B30A Series User s Guide 198 ...
Страница 210: ...Chapter 14 Interface Group VMG5313 B10A B30A Series User s Guide 210 ...
Страница 218: ...Chapter 15 USB Service VMG5313 B10A B30A Series User s Guide 218 ...
Страница 232: ...Chapter 17 Firewall VMG5313 B10A B30A Series User s Guide 232 ...
Страница 240: ...Chapter 19 Parental Control VMG5313 B10A B30A Series User s Guide 240 ...
Страница 250: ...Chapter 21 Certificates VMG5313 B10A B30A Series User s Guide 250 ...
Страница 296: ...Chapter 23 Voice VMG5313 B10A B30A Series User s Guide 296 ...
Страница 300: ...Chapter 24 Log VMG5313 B10A B30A Series User s Guide 300 ...
Страница 308: ...Chapter 27 xDSL Statistics VMG5313 B10A B30A Series User s Guide 308 ...
Страница 318: ...Chapter 30 Remote Management VMG5313 B10A B30A Series User s Guide 318 ...
Страница 322: ...Chapter 32 TR 064 VMG5313 B10A B30A Series User s Guide 322 ...
Страница 332: ...Chapter 36 Log Setting VMG5313 B10A B30A Series User s Guide 332 ...
Страница 335: ...Chapter 37 Firmware Upgrade VMG5313 B10A B30A Series User s Guide 335 Figure 176 Error Message ...
Страница 336: ...Chapter 37 Firmware Upgrade VMG5313 B10A B30A Series User s Guide 336 ...
Страница 352: ...Chapter 40 Troubleshooting VMG5313 B10A B30A Series User s Guide 352 ...
Страница 353: ...353 PART III Appendices Appendices contain general information Some information may not apply to your device ...
Страница 354: ...354 ...
Страница 374: ...Appendix B Wireless LANs VMG5313 B10A B30A Series User s Guide 374 ...
Страница 390: ...Appendix E Legal Information VMG5313 B10A B30A Series User s Guide 390 ...