HP 6600 Security Configuration Manual page 265

Table of Contents

Advertisement

Figure 91 Encapsulation by security protocols in different modes
Authentication algorithms and encryption algorithms
1.
Authentication algorithms:
IPsec uses hash algorithms to perform authentication. A hash algorithm produces a fixed-length
digest for an arbitrary-length message. IPsec peers respectively calculate message digests for each
packet. If the resulting digests are identical, the packet is considered intact.
IPsec supports the following hash algorithms for authentication:
MD5—Takes a message of arbitrary length as input and produces a 128-bit message digest.
SHA-1—Takes a message of a maximum length less than the 64th power of 2 in bits as input
and produces a 160-bit message digest.
Compared with SHA-1, MD5 is faster but less secure.
2.
Encryption algorithms:
IPsec mainly uses symmetric encryption algorithms, which encrypt and decrypt data by using the
same keys. The following encryption algorithms are available for IPsec on the device:
DES—Encrypts a 64-bit plain text block with a 56-bit key. DES is the least secure but the fastest
algorithm. It is sufficient for general security requirements.
3DES—Encrypts plain text data with three 56-bit DES keys. The key length totals up to 168 bits.
It provides moderate security strength and is slower than DES.
AES—Encrypts plain text data with a 128-bit, 192-bit, or 256-bit key. AES provides the highest
security strength and is slower than 3DES.
IPsec SA setup modes
IPsec SA setup modes include the following:
Manual mode—In this mode, you manually configure and maintain all SA settings. Advanced
features like periodical key update are not available. However, this mode implements IPsec
independently of IKE.
ISAKMP mode—In this mode, IKE automatically negotiates and maintains IPsec SAs for IPsec.
GDOI mode—This mode is used to build a group encrypted transport (GET) VPN. The SAs and keys
are managed by the key server in a centralized way, and are issued to the group members.
If the number of IPsec tunnels in your network is small, use the manual mode. If the number of IPsec
tunnels is large, use the ISAKMP mode.
IPsec tunnel
An IPsec tunnel is a bidirectional channel created between two peers. An IPsec tunnel comprises one or
more pairs of SAs.
251

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hsr6600

Table of Contents