VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manual de usuario Pagina 134

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 162
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 133
vShield Administration Guide
134 VMware, Inc.
Terminology
IPSecisaframeworkofopenstandards.TherearemanytechnicaltermsinthelogsofthevShieldEdgeand
otherVPNappliancesthatyoucanusetotroubleshoottheIPSECVPN.
ISAKMP(InternetSecurityAssociationandKeyManagementProtocol)isaprotocoldefinedbyRFC2408
forestablishingSecurityAssociations(SA)andcryptographickeysinanInternetenvironment.ISAKMP
onlyprovidesaframeworkforauthenticationandkeyexchangeandisdesignedtobekeyexchange
independent.
Oakleyisakeyagreementprotocolthatallowsauthenticatedpartiestoexchangekeyingmaterialacross
aninsecureconnectionusingtheDiffieHellmankeyexchangealgorithm.
IKE(InternetKeyExchange)isacombinationofISAKMPframeworkandOakley.vSHieldEdgeprovides
IKEv2.
DiffieHellman(DH)keyexchangeisacryptographicprotocolthatallowstwopartiesthathavenoprior
knowledgeofeachothertojointlyestablishasharedsecretkeyoveraninsecurecommunicationschannel.
VSEsupportsDHgroup2(1024bits)andgroup5(1536bits).
IKE Phase 1 and Phase 2
IKEisastandardmethodusedtoarrangesecure,authenticatedcommunications.
Phase1setsupmutualauthenticationofthepeers,negotiatescryptographicparameters,andcreatessession
keys.ThePhase1parametersusedbythevShieldEdgeare:
Mainmode
TripleDES/AES[Configurable]
SHA1
MODPgroup2(1024bits)
presharedsecret[Configurable]
SAlifetimeof28800seconds(eighthours)withnokbytesrekeying
ISAKMPaggressivemodedisabled
IKEPhase2negotiatesanIPSectunnelbycreatingkeyingmaterialfortheIPSectunneltouse(eitherbyusing
theIKEphaseonekeysasabaseorbyperforminganewkeyexchange).TheIKEPhase2parameters
supportedbyvShieldEdgeare:
TripleDES/AES[WillmatchthePhase1setting]
SHA1
ESPtunnelmode
MODPgroup2(1024bits)
Perfectforwardsecrecyforrekeying
SAlifetimeof3600seconds(onehour)withnokbytesrekeying
SelectorsforallIPprotocols,allports,betweenthetwonetworks,usingIPv4subnets
ThevShieldEdgesupportsMainModeforPhase1andQuickModeforPhase2.
ThevShieldEdgeproposesapolicythatrequiresPSK,3DES/AES128,sha1,andDHGroup2/5.Thepeermust
acceptthispolicy;otherwise,
thenegotiationphasefails.
ThisexampleshowsanexchangeofPhase1negotiationinitiatedfromavShieldEdgetoaCiscodevice.
N
OTEForvShieldEdgetovShieldEdgeIPSECtunnels,youcanusethissamescenariosbysettingupthe
secondvShieldEdgeastheremotegateway.
Vista de pagina 133
1 2 ... 129 130 131 132 133 134 135 136 137 138 139 ... 161 162

Comentarios a estos manuales

Sin comentarios