Nortel BCM50 Configuration Manual page 528

Nortel bcm50: network guide
Table of Contents

Advertisement

528
Appendix A VPN overview
The encryption level you choose is made of three components:
the protocol
the encryption method
the authentication method
Protocol
The protocol can be ESP or AH.
ESP
Encapsulating Security Payload (ESP) provides data integrity, source authentication and
confidentiality for IP datagrams by encrypting the payload data to be protected. ESP uses the
Data Encryption Standard (DES) and Triple DES algorithms.
AH
Authentication Header (AH) provides data integrity and source authentication. The AH
method does not encrypt data.
Note: The use of a NAT device in the IPSec tunnel path can sometimes cause the AH
method to report a security violation. This occurs because the NAT device changes the IP
Address of an AH authenticated packet causing the authentication of this packet to fail.
Encryption method
The encryption method can be Triple DES, 56-bit DES or 40-bit DES. Triple DES is the strongest
encryption and 40-bit DES is the weakest encryption.
Triple DES
Triple DES is an encryption block cipher algorithm that uses a 168-bit key. It uses the DES
encryption algorithm three times. The first 56 bits of the key is used to encrypt the data, then
the second 56 bits is used to decrypt the data. Finally, the data is encrypted once again with the
third 56 bits. These three steps triple the complexity of the algorithm.
56-bit DES
56-bit DES is an encryption block cipher algorithm that uses a 56-bit key (with 8 bits of parity)
over a 64-bit block. The 56 bits of the key are transformed and combined with a 64-bit
message through a complex process of 16 steps.
40-bit DES
40-bit DES is an encryption block cipher algorithm that uses a 40-bit key (with 8 bits of parity)
over a 64-bit block. The 40 bits of the key are transformed and combined with a 64-bit
message through a complex process of 16 steps. Both 40- and 56-bit DES require the same
processing demands, so you should use 56-bit DES unless local encryption laws prohibit
doing so.
NN40020-603
NN40020-603

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents