VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Uživatelský manuál Strana 134

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 162
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 133
vShield Administration Guide
134 VMware, Inc.
Terminology
IPSecisaframeworkofopenstandards.TherearemanytechnicaltermsinthelogsofthevShieldEdgeand
otherVPNappliancesthatyoucanusetotroubleshoottheIPSECVPN.
ISAKMP(InternetSecurityAssociationandKeyManagementProtocol)isaprotocoldefinedbyRFC2408
forestablishingSecurityAssociations(SA)andcryptographickeysinanInternetenvironment.ISAKMP
onlyprovidesaframeworkforauthenticationandkeyexchangeandisdesignedtobekeyexchange
independent.
Oakleyisakeyagreementprotocolthatallowsauthenticatedpartiestoexchangekeyingmaterialacross
aninsecureconnectionusingtheDiffieHellmankeyexchangealgorithm.
IKE(InternetKeyExchange)isacombinationofISAKMPframeworkandOakley.vSHieldEdgeprovides
IKEv2.
DiffieHellman(DH)keyexchangeisacryptographicprotocolthatallowstwopartiesthathavenoprior
knowledgeofeachothertojointlyestablishasharedsecretkeyoveraninsecurecommunicationschannel.
VSEsupportsDHgroup2(1024bits)andgroup5(1536bits).
IKE Phase 1 and Phase 2
IKEisastandardmethodusedtoarrangesecure,authenticatedcommunications.
Phase1setsupmutualauthenticationofthepeers,negotiatescryptographicparameters,andcreatessession
keys.ThePhase1parametersusedbythevShieldEdgeare:
Mainmode
TripleDES/AES[Configurable]
SHA1
MODPgroup2(1024bits)
presharedsecret[Configurable]
SAlifetimeof28800seconds(eighthours)withnokbytesrekeying
ISAKMPaggressivemodedisabled
IKEPhase2negotiatesanIPSectunnelbycreatingkeyingmaterialfortheIPSectunneltouse(eitherbyusing
theIKEphaseonekeysasabaseorbyperforminganewkeyexchange).TheIKEPhase2parameters
supportedbyvShieldEdgeare:
TripleDES/AES[WillmatchthePhase1setting]
SHA1
ESPtunnelmode
MODPgroup2(1024bits)
Perfectforwardsecrecyforrekeying
SAlifetimeof3600seconds(onehour)withnokbytesrekeying
SelectorsforallIPprotocols,allports,betweenthetwonetworks,usingIPv4subnets
ThevShieldEdgesupportsMainModeforPhase1andQuickModeforPhase2.
ThevShieldEdgeproposesapolicythatrequiresPSK,3DES/AES128,sha1,andDHGroup2/5.Thepeermust
acceptthispolicy;otherwise,
thenegotiationphasefails.
ThisexampleshowsanexchangeofPhase1negotiationinitiatedfromavShieldEdgetoaCiscodevice.
N
OTEForvShieldEdgetovShieldEdgeIPSECtunnels,youcanusethissamescenariosbysettingupthe
secondvShieldEdgeastheremotegateway.
Zobrazit stránku 133
1 2 ... 129 130 131 132 133 134 135 136 137 138 139 ... 161 162

Komentáře k této Příručce

Žádné komentáře