Ipsec Features Supported By The Spu - Huawei quidway s7700 Configuration Manual

Smart routing switch
Hide thumbs Also See for quidway s7700:
Table of Contents

Advertisement

Quidway S7700 Smart Routing Switch
Configuration Guide - SPU
Figure 4-2 Packets format in tunnel mode
Protocol
AH-ESP
l
l

4.2 IPSec Features Supported by the SPU

The SPU supports IPSec tunnel established in manual mode or IKE negotiation mode.
The SPU implements the IPSec functions described in
IPSec peers can adopt various security protection measures (authentication, encryption, or both)
on different data flows.
The IPSec configuration roadmap is as follows:
1.
2.
3.
4.
Issue 01 (2011-07-15)
Mode
AH
new IP Header AH
new IP
ESP
Header
new IP Header
Authentication algorithm and encryption algorithm
– IPSec can use the Message Digest 5 (MD5) algorithm or Secure Hash Algorithm
(SHA-1) for authentication. The MD5 algorithm computes faster than the SHA-1
algorithm, whereas the SHA-1 algorithm is more secure than the MD5 algorithm.
– IPSec can use the DES, Triple Data Encryption Standard (3DES), and Advanced
Encryption Standard (AES) algorithms for encryption. The ASE algorithm encrypts
plain text by using a key of 128 bits, 192 bits, or 256 bits.
Negotiation mode
IPSec uses two negotiation modes to establish SAs: manual mode (manual) and IKE
negotiation mode (isakmp).
Define data flows to be protected by using an ACL.
Configure an IPSec proposal to specify the security protocol, authentication algorithm,
encryption algorithm, and encapsulation mode.
Configure an IPSec policy or an IPSec policy group to specify the association between data
flows and the IPSec proposal (protection measures for the data flows), SA negotiation
mode, peer IP address (start and end points of the protection path), required key, and SA
lifetime.
Apply the IPSec policy on an interface of the switch.
In addition, IPSec supports MPLS VPN access. You can implement this function by:
l Associating a VPN instance with an SA
l Configuring the switch as a PE and associating the VPN instance with the PE interface
connected to the CE
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
tunnel
raw IP Header
TCP Header
raw IP
ESP
TCP Header
Header
AH
ESP
raw IP Header
4 IPSec Configuration
data
ESP Tail ESP Auth data
data
data ESP TailESP Auth data
TCP Header
4.1 IPSec
Overview.
113

Advertisement

Table of Contents
loading

Table of Contents