Chapter 21 IPSec
VSG1432-B101 Series User’s Guide
260
21.4.4 Negotiation Mode
The phase 1
Negotiation Mode
you select determines how the Security
Association (SA) will be established for each connection through IKE negotiations.
•
Main Mode
ensures the highest level of security when the communicating
parties are negotiating authentication (phase 1). It uses 6 messages in three
round trips: SA negotiation, Diffie-Hellman exchange and an exchange of
nonces (a nonce is a random number). This mode features identity protection
(your identity is not revealed in the negotiation).
•
Aggressive Mode
is quicker than
Main Mode
because it eliminates several
steps when the communicating parties are negotiating authentication (phase 1).
However the trade-off is that faster speed limits its negotiating power and it also
does not provide identity protection. It is useful in remote access situations
where the address of the initiator is not know by the responder and both parties
want to use pre-shared key authentication.
21.4.5 IPSec and NAT
Read this section if you are running IPSec on a host computer behind the ZyXEL
Device.
NAT is incompatible with the
AH
protocol in both
Transport
and
Tunnel
mode.
An IPSec VPN using the
AH
protocol digitally signs the outbound packet, both data
payload and headers, with a hash value appended to the packet. When using
AH
protocol, packet contents (the data payload) are not encrypted.
A NAT device in between the IPSec endpoints will rewrite either the source or
destination address with one of its own choosing. The VPN device at the receiving
end will verify the integrity of the incoming packet by computing its own hash
value, and complain that the hash value appended to the received packet doesn't
match. The VPN device at the receiving end doesn't know about the NAT in the
middle, so it assumes that the data has been maliciously altered.
IPSec using
ESP
in
Tunnel
mode encapsulates the entire original packet
(including headers) in a new IP packet. The new IP packet's source address is the
outbound address of the sending VPN gateway, and its destination address is the
inbound address of the VPN device at the receiving end. When using
ESP
protocol
with authentication, the packet contents (in this case, the entire original packet)
are encrypted. The encrypted contents, but not the new headers, are signed with
a hash value appended to the packet.
Tunnel
mode
ESP
with authentication is compatible with NAT because integrity
checks are performed over the combination of the "original header plus original
payload," which is unchanged by a NAT device.
Содержание VSG1432-B101 - V1.10
Страница 2: ......
Страница 8: ...Safety Warnings VSG1432 B101 Series User s Guide 8 ...
Страница 10: ...Contents Overview VSG1432 B101 Series User s Guide 10 ...
Страница 20: ...Table of Contents VSG1432 B101 Series User s Guide 20 ...
Страница 21: ...21 PART I User s Guide ...
Страница 22: ...22 ...
Страница 40: ...Chapter 2 The Web Configurator VSG1432 B101 Series User s Guide 40 ...
Страница 67: ...67 PART II Technical Reference ...
Страница 68: ...68 ...
Страница 74: ...Chapter 5 Network Map and Status Screens VSG1432 B101 Series User s Guide 74 ...
Страница 146: ...Chapter 8 Home Networking VSG1432 B101 Series User s Guide 146 ...
Страница 150: ...Chapter 9 Static Routing VSG1432 B101 Series User s Guide 150 ...
Страница 174: ...Chapter 11 Policy Forwarding VSG1432 B101 Series User s Guide 174 ...
Страница 192: ...Chapter 12 Network Address Translation NAT VSG1432 B101 Series User s Guide 192 ...
Страница 198: ...Chapter 13 Dynamic DNS Setup VSG1432 B101 Series User s Guide 198 ...
Страница 224: ...Chapter 16 Firewall VSG1432 B101 Series User s Guide 224 ...
Страница 230: ...Chapter 18 Parental Control VSG1432 B101 Series User s Guide 230 ...
Страница 278: ...Chapter 25 Traffic Status VSG1432 B101 Series User s Guide 278 ...
Страница 282: ...Chapter 26 IGMP Status VSG1432 B101 Series User s Guide 282 ...
Страница 290: ...Chapter 28 Remote Management VSG1432 B101 Series User s Guide 290 ...
Страница 294: ...Chapter 29 Time Settings VSG1432 B101 Series User s Guide 294 ...
Страница 298: ...Chapter 30 Logs Setting VSG1432 B101 Series User s Guide 298 ...
Страница 314: ...Chapter 34 Troubleshooting VSG1432 B101 Series User s Guide 314 ...
Страница 344: ...Appendix A Setting up Your Computer s IP Address VSG1432 B101 Series User s Guide 344 ...
Страница 354: ...Appendix B IP Addresses and Subnetting VSG1432 B101 Series User s Guide 354 ...
Страница 364: ...Appendix C Pop up Windows JavaScripts and Java Permissions VSG1432 B101 Series User s Guide 364 ...
Страница 380: ...Appendix D Wireless LANs VSG1432 B101 Series User s Guide 380 ...
Страница 408: ...Index VSG1432 B101 Series User s Guide 408 ...