THOMSON SpeedTouch 608WL Configuration Manual page 15

Wireless business dsl router ipsec configuration guide
Hide thumbs Also See for SpeedTouch 608WL:
Table of Contents

Advertisement

Internet Key Exchange
Security Associations
Tunnel Mode
Transport Mode
E-DOC-CTC-20051017-0169 v1.0
The Internet Key Exchange (IKE) protocol is the negotiation protocol used to establish
an SA by negotiating security protocols and exchanging keys. First the IKE SA is set
up, then the IKE channel acts as a signalling channel to negotiate a general purpose
SA.
Within the IKE protocol, two phases are distinguished to set up a tunnel between
two peers:
Phase 1: negotiate a bi-directional IKE SA functioning as a signalling channel to
negotiate the Phase 2 SAs.
Phase 2: negotiate unidirectional IPSec Security Associations that will carry
general purpose traffic.
The IKE SA is bidirectional, whereas the Phase 2 SA is unidirectional: one Security
Association must be set up in each direction. The initiator and responder cookies
uniquely identify an IKE SA while each PH2 SA is uniquely identified by a SPI
(Security Parameter Index) value.
Per convention, throughout this document the IKE SA is referred to as the Phase 1
SA and the ESP SAs are referred to as the Phase 2 SA:
Phase 1 SA = IKE SA = secure Phase 1 tunnel
A pair of Phase 2 SAs = a secure Phase 2 tunnel
Using tunnel mode, the complete IP packet (including its IP header) is encapsulated
and a new IP header is attached. This allows for the original source and destination IP
addresses to be hidden from the outside world.
Red network
SpeedTouch620 [1]
node
A
A B
Red LAN
In transport mode, the IP header is transported unmodified. The use of transport
mode is limited to connections where the security gateway is acting as a host, e.g.,
for network management applications. When the SpeedTouch™ is managed from a
remote location via a VPN connection, transport mode can be used, because in this
case the SpeedTouch™ is the end user of this information stream.
IPSec: Concept for secure IP connections
Phase 1
Phase 1 (IKE) SA
SA (ESP/AH)
SA (ESP/AH)
Phase 2 tunnel
SpeedTouch620 [2]
B
C
C D A B
Black LAN
Chapter 1
Red network
node
D
A B
Red LAN
13

Advertisement

Table of Contents
loading

This manual is also suitable for:

Speedtouch 620

Table of Contents