3.1.3
IPSec
IPSec is an industry-standard method for encrypting networking communications
that was designed specifically to work with IP networking. IPSec clients are
available from a variety of vendors. Clients known to interoperate with the WLAN
Secure Server IPSec implementation include ones from SafeNet, Netscreen, PGP,
and Certicom/Movian.
The IPSec standard does not include a specification for user-level authentication.
It does provide for machine-to-machine authentication using either certificate-
based or shared secret-based authentication. The WLAN Security System only
supports shared secret IPSec authentication.
IPSec operates in two phases and uses encryption and a secure hash function for
each phase. The first phase, Internet Key Exchange (IKE) sets up a session key used
in the second phase to do the actual encryption. The second phase, Encapsulating
Security Payload (ESP), does the actual data encryption. Both the IKE and ESP
phases can use Data Encryption Standard (DES), Triple DES, Blowfish, or CAST
encryption.
The secure hash used for data integrity in both the IKE and ESP phases can be
either Secure Hash Algorithm 1 (SHA-1) or Message Digest 5 (MD5).
IPSec uses the Diffie-Hellman Public-Key-Interchange (PKI) to generate the per-
session encryption key during the IKE phase. Supported versions of the Diffie-
Hellman key exchange include Group 1, 2, and 5.
In general, the client and the SMC system negotiate the type of hash, encryption,
and key-exchange algorithms. Configuration of IPSec on the WLAN Security
System consists primarily of noting which algorithm the SMC system is prepared
to negotiate. It is up to the client system to propose algorithms, and the SMC server
either agrees or not.
3.1.4
General Considerations
Selection of a particular VPN protocol involves several factors:
• necessity
• performance
• security
• availability
Necessity
You must first determine whether you require VPN Security as it imposes a fairly
heavy administrative burden and it slows the throughput of data between a client
and a WLAN Access Manager.
VPN Security (Airwave Security)
3-3
Need help?
Do you have a question about the ELITECONNECT SMC2502W and is the answer not in the manual?