
vShield Administration Guide
134 VMware, Inc.
Terminology
IPSecisaframeworkofopenstandards.TherearemanytechnicaltermsinthelogsofthevShieldEdgeand
otherVPNappliancesthatyoucanusetotroubleshoottheIPSECVPN.
ISAKMP(InternetSecurityAssociationandKeyManagementProtocol)isaprotocoldefinedbyRFC2408
forestablishingSecurityAssociations(SA)andcryptographickeysinanInternetenvironment.ISAKMP
onlyprovidesaframeworkforauthenticationandkeyexchangeandisdesignedtobekeyexchange
independent.
Oakleyisakey‐agreementprotocolthatallowsauthenticatedpartiestoexchangekeyingmaterialacross
aninsecureconnectionusingtheDiffie‐Hellmankeyexchangealgorithm.
IKE(InternetKeyExchange)isacombinationofISAKMPframeworkandOakley.vSHieldEdgeprovides
IKEv2.
Diffie‐Hellman(DH)keyexchangeisacryptographicprotocolthatallowstwopartiesthathavenoprior
knowledgeofeachothertojointlyestablishasharedsecretkeyoveraninsecurecommunicationschannel.
VSEsupportsDHgroup2(1024bits)andgroup5(1536bits).
IKE Phase 1 and Phase 2
IKEisastandardmethodusedtoarrangesecure,authenticatedcommunications.
Phase1setsupmutualauthenticationofthepeers,negotiatescryptographicparameters,andcreatessession
keys.ThePhase1parametersusedbythevShieldEdgeare:
Mainmode
TripleDES/AES[Configurable]
SHA‐1
MODPgroup2(1024bits)
pre‐sharedsecret[Configurable]
SAlifetimeof28800seconds(eighthours)withnokbytesrekeying
ISAKMPaggressivemodedisabled
IKEPhase2negotiatesanIPSectunnelbycreatingkeyingmaterialfortheIPSectunneltouse(eitherbyusing
theIKEphaseonekeysasabaseorbyperforminganewkeyexchange).TheIKEPhase2parameters
supportedbyvShieldEdgeare:
TripleDES/AES[WillmatchthePhase1setting]
SHA‐1
ESPtunnelmode
MODPgroup2(1024bits)
Perfectforwardsecrecyforrekeying
SAlifetimeof3600seconds(onehour)withnokbytesrekeying
SelectorsforallIPprotocols,allports,betweenthetwonetworks,usingIPv4subnets
ThevShieldEdgesupportsMainModeforPhase1andQuickModeforPhase2.
ThevShieldEdgeproposesapolicythatrequiresPSK,3DES/AES128,sha1,andDHGroup2/5.Thepeermust
acceptthispolicy;otherwise,
thenegotiationphasefails.
ThisexampleshowsanexchangeofPhase1negotiationinitiatedfromavShieldEdgetoaCiscodevice.
N
OTEForvShieldEdgetovShieldEdgeIPSECtunnels,youcanusethissamescenariosbysettingupthe
secondvShieldEdgeastheremotegateway.
Commentaires sur ces manuels