Ipsec Headers - HP ProCurve Secure Router 7203 dl Advanced Management And Configuration Manual

Secure router
Hide thumbs Also See for ProCurve Secure Router 7203 dl:
Table of Contents

Advertisement

IPSec Headers

Operating on the Network Level of the Open Systems Interconnection (OSI)
model, IPSec authenticates the endpoints of a tunnel by encapsulating an IP
packet with an IPSec header. The IPSec header is either an Authentication
Header (AH) and/or an Encapsulation Security Payload (ESP) header.
The placement of the header in the packet differs according to the mode in
which IPSec is operating. IPSec can operate in either transport or tunnel
mode. In transport mode, the IPSec header encapsulates the payload at the
Transport (TCP or UDP) Layer (Layer 4). An IP header then encapsulates the
IPSec packet. (See Figure 8-1.)
Transport mode is typically used for local security applications. It provides
flexibility and security, but it can be difficult and expensive to implement
because the host must add the IPSec header before it adds an IP header and
transmits the data. That is, every host must support IPSec.
Transport mode
IPSec
Payload
header
VPN client
Tunnel mode
IP
Payload
header
Figure 8-1. IPSec Transport and Tunnel Mode
IP
header
Internet
Router
VPN tunnel
IPSec
New IP
header
header
Internet
Router
VPN tunnel
Virtual Private Networks
Overview
VPN client
VPN client
8-5

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve secure router 7102 dl

Table of Contents