NETGEAR DG834 ADSL Firewall Router DG834 DG834 Reference Manual page 197

Adsl firewall router
Hide thumbs Also See for DG834 ADSL Firewall Router DG834 DG834:
Table of Contents

Advertisement

Reference Manual for the ADSL Firewall Router DG834
VPN Tunnel
A
B
DG834 VPN Firewall
DG834 VPN Firewall
PCs
PCs
Figure D-5: VPN Tunnel SA
The SA contains all the information necessary for gateway A to negotiate a secure and encrypted
communication stream with gateway B. This communication is often referred to as a "tunnel." The
gateways contain this information so that it does not have to be loaded onto every computer
connected to the gateways.
Each gateway must negotiate its Security Association with another gateway using the parameters
and processes established by IPSec. As illustrated below, the most common method of
accomplishing this process is via the Internet Key Exchange (IKE) protocol which automates some
of the negotiation procedures. Alternatively, you can configure your gateways using manual key
exchange, which involves manually configuring each paramter on both gateways.
IPSec Security Association IKE
VPN Tunnel Negotiation Steps
VPN Gateway
VPN Gateway
Figure D-6: IPSec SA negotiation
1. The IPSec software on Host A initiates the IPSec process in an attempt to communicate
with Host B. The two computers then begin the Internet Key Exchange (IKE) process.
Virtual Private Networking
D-9
202-10005-05, June 2005

Advertisement

Table of Contents
loading

Table of Contents