Ipsec; General Considerations; Necessity - SMC Networks ELITECONNECT SMC2502W User Manual

Wlan security system
Hide thumbs Also See for ELITECONNECT SMC2502W:
Table of Contents

Advertisement

3.1.3

IPSec

IPSec is an industry-standard method for encrypting networking communications
that was designed specifically to work with IP networking. IPSec clients are
available from a variety of vendors. Clients known to interoperate with the WLAN
Secure Server IPSec implementation include ones from SafeNet, Netscreen, PGP,
and Certicom/Movian.
The IPSec standard does not include a specification for user-level authentication.
It does provide for machine-to-machine authentication using either certificate-
based or shared secret-based authentication. The WLAN Security System only
supports shared secret IPSec authentication.
IPSec operates in two phases and uses encryption and a secure hash function for
each phase. The first phase, Internet Key Exchange (IKE) sets up a session key used
in the second phase to do the actual encryption. The second phase, Encapsulating
Security Payload (ESP), does the actual data encryption. Both the IKE and ESP
phases can use Data Encryption Standard (DES), Triple DES, Blowfish, or CAST
encryption.
The secure hash used for data integrity in both the IKE and ESP phases can be
either Secure Hash Algorithm 1 (SHA-1) or Message Digest 5 (MD5).
IPSec uses the Diffie-Hellman Public-Key-Interchange (PKI) to generate the per-
session encryption key during the IKE phase. Supported versions of the Diffie-
Hellman key exchange include Group 1, 2, and 5.
In general, the client and the SMC system negotiate the type of hash, encryption,
and key-exchange algorithms. Configuration of IPSec on the WLAN Security
System consists primarily of noting which algorithm the SMC system is prepared
to negotiate. It is up to the client system to propose algorithms, and the SMC server
either agrees or not.
3.1.4

General Considerations

Selection of a particular VPN protocol involves several factors:

• necessity

• performance
• security
• availability
Necessity
You must first determine whether you require VPN Security as it imposes a fairly
heavy administrative burden and it slows the throughput of data between a client
and a WLAN Access Manager.
VPN Security (Airwave Security)
3-3

Advertisement

Table of Contents
loading

This manual is also suitable for:

Eliteconnect smc2504w2502w - annexe 12504w - annexe 1

Table of Contents