VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manuel d'utilisateur Page 134

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 162
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 133
vShield Administration Guide
134 VMware, Inc.
Terminology
IPSecisaframeworkofopenstandards.TherearemanytechnicaltermsinthelogsofthevShieldEdgeand
otherVPNappliancesthatyoucanusetotroubleshoottheIPSECVPN.
ISAKMP(InternetSecurityAssociationandKeyManagementProtocol)isaprotocoldefinedbyRFC2408
forestablishingSecurityAssociations(SA)andcryptographickeysinanInternetenvironment.ISAKMP
onlyprovidesaframeworkforauthenticationandkeyexchangeandisdesignedtobekeyexchange
independent.
Oakleyisakeyagreementprotocolthatallowsauthenticatedpartiestoexchangekeyingmaterialacross
aninsecureconnectionusingtheDiffieHellmankeyexchangealgorithm.
IKE(InternetKeyExchange)isacombinationofISAKMPframeworkandOakley.vSHieldEdgeprovides
IKEv2.
DiffieHellman(DH)keyexchangeisacryptographicprotocolthatallowstwopartiesthathavenoprior
knowledgeofeachothertojointlyestablishasharedsecretkeyoveraninsecurecommunicationschannel.
VSEsupportsDHgroup2(1024bits)andgroup5(1536bits).
IKE Phase 1 and Phase 2
IKEisastandardmethodusedtoarrangesecure,authenticatedcommunications.
Phase1setsupmutualauthenticationofthepeers,negotiatescryptographicparameters,andcreatessession
keys.ThePhase1parametersusedbythevShieldEdgeare:
Mainmode
TripleDES/AES[Configurable]
SHA1
MODPgroup2(1024bits)
presharedsecret[Configurable]
SAlifetimeof28800seconds(eighthours)withnokbytesrekeying
ISAKMPaggressivemodedisabled
IKEPhase2negotiatesanIPSectunnelbycreatingkeyingmaterialfortheIPSectunneltouse(eitherbyusing
theIKEphaseonekeysasabaseorbyperforminganewkeyexchange).TheIKEPhase2parameters
supportedbyvShieldEdgeare:
TripleDES/AES[WillmatchthePhase1setting]
SHA1
ESPtunnelmode
MODPgroup2(1024bits)
Perfectforwardsecrecyforrekeying
SAlifetimeof3600seconds(onehour)withnokbytesrekeying
SelectorsforallIPprotocols,allports,betweenthetwonetworks,usingIPv4subnets
ThevShieldEdgesupportsMainModeforPhase1andQuickModeforPhase2.
ThevShieldEdgeproposesapolicythatrequiresPSK,3DES/AES128,sha1,andDHGroup2/5.Thepeermust
acceptthispolicy;otherwise,
thenegotiationphasefails.
ThisexampleshowsanexchangeofPhase1negotiationinitiatedfromavShieldEdgetoaCiscodevice.
N
OTEForvShieldEdgetovShieldEdgeIPSECtunnels,youcanusethissamescenariosbysettingupthe
secondvShieldEdgeastheremotegateway.
Vue de la page 133
1 2 ... 129 130 131 132 133 134 135 136 137 138 139 ... 161 162

Commentaires sur ces manuels

Pas de commentaire