VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manuale Utente Pagina 134

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
Vedere la pagina 133
vShield Administration Guide
134 VMware, Inc.
Terminology
IPSecisaframeworkofopenstandards.TherearemanytechnicaltermsinthelogsofthevShieldEdgeand
otherVPNappliancesthatyoucanusetotroubleshoottheIPSECVPN.
ISAKMP(InternetSecurityAssociationandKeyManagementProtocol)isaprotocoldefinedbyRFC2408
forestablishingSecurityAssociations(SA)andcryptographickeysinanInternetenvironment.ISAKMP
onlyprovidesaframeworkforauthenticationandkeyexchangeandisdesignedtobekeyexchange
independent.
Oakleyisakeyagreementprotocolthatallowsauthenticatedpartiestoexchangekeyingmaterialacross
aninsecureconnectionusingtheDiffieHellmankeyexchangealgorithm.
IKE(InternetKeyExchange)isacombinationofISAKMPframeworkandOakley.vSHieldEdgeprovides
IKEv2.
DiffieHellman(DH)keyexchangeisacryptographicprotocolthatallowstwopartiesthathavenoprior
knowledgeofeachothertojointlyestablishasharedsecretkeyoveraninsecurecommunicationschannel.
VSEsupportsDHgroup2(1024bits)andgroup5(1536bits).
IKE Phase 1 and Phase 2
IKEisastandardmethodusedtoarrangesecure,authenticatedcommunications.
Phase1setsupmutualauthenticationofthepeers,negotiatescryptographicparameters,andcreatessession
keys.ThePhase1parametersusedbythevShieldEdgeare:
Mainmode
TripleDES/AES[Configurable]
SHA1
MODPgroup2(1024bits)
presharedsecret[Configurable]
SAlifetimeof28800seconds(eighthours)withnokbytesrekeying
ISAKMPaggressivemodedisabled
IKEPhase2negotiatesanIPSectunnelbycreatingkeyingmaterialfortheIPSectunneltouse(eitherbyusing
theIKEphaseonekeysasabaseorbyperforminganewkeyexchange).TheIKEPhase2parameters
supportedbyvShieldEdgeare:
TripleDES/AES[WillmatchthePhase1setting]
SHA1
ESPtunnelmode
MODPgroup2(1024bits)
Perfectforwardsecrecyforrekeying
SAlifetimeof3600seconds(onehour)withnokbytesrekeying
SelectorsforallIPprotocols,allports,betweenthetwonetworks,usingIPv4subnets
ThevShieldEdgesupportsMainModeforPhase1andQuickModeforPhase2.
ThevShieldEdgeproposesapolicythatrequiresPSK,3DES/AES128,sha1,andDHGroup2/5.Thepeermust
acceptthispolicy;otherwise,
thenegotiationphasefails.
ThisexampleshowsanexchangeofPhase1negotiationinitiatedfromavShieldEdgetoaCiscodevice.
N
OTEForvShieldEdgetovShieldEdgeIPSECtunnels,youcanusethissamescenariosbysettingupthe
secondvShieldEdgeastheremotegateway.
Vedere la pagina 133
1 2 ... 129 130 131 132 133 134 135 136 137 138 139 ... 161 162

Commenti su questo manuale

Nessun commento