What You Need To Know; Ike Sa (Ike Phase 1) Overview - ZyXEL Communications NBG5715 User Manual

Simultaneous dual-band wireless n media router
Hide thumbs Also See for NBG5715:
Table of Contents

Advertisement

Chapter 18 IPSec VPN

18.3 What You Need To Know

A VPN tunnel is usually established in two phases. Each phase establishes a security association
(SA), a contract indicating what security parameters the NBG5715 and the remote IPSec router will
use.
The first phase establishes an Internet Key Exchange (IKE) SA between the NBG5715 and remote
IPSec router. The second phase uses the IKE SA to securely establish an IPSec SA through which
the NBG5715 and remote IPSec router can send data between computers on the local network and
remote network. The following figure illustrates this.
Figure 77 VPN: IKE SA and IPSec SA
In this example, a computer in network A is exchanging data with a computer in network B. Inside
networks A and B, the data is transmitted the same way data is normally transmitted in the
networks. Between routers X and Y, the data is protected by tunneling, encryption, authentication,
and other security features of the IPSec SA. The IPSec SA is established securely using the IKE SA
that routers X and Y established first.

18.3.1 IKE SA (IKE Phase 1) Overview

The IKE SA provides a secure connection between the NBG5715 and remote IPSec router.
It takes several steps to establish an IKE SA. The negotiation mode determines the number of steps
to use. There are two negotiation modes--main mode and aggressive mode. Main mode provides
better security, while aggressive mode is faster.
Both routers must use the same negotiation mode.
These modes are discussed in more detail in
various examples in the rest of this section.
IP Addresses of the NBG5715 and Remote IPSec Router
In the NBG5715, you have to specify the IP addresses of the NBG5715 and the remote IPSec router
to establish an IKE SA.
You can usually provide a static IP address or a domain name for the NBG5715. Sometimes, your
NBG5715 might also offer another alternative, such as using the IP address of a port or interface.
122
IPSec SA
X
IKE SA
Section 18.7.4 on page
Y
138. Main mode is used in
NBG5715 User's Guide

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents