DPX8000 Series Deep Service Switching Gateway User
Configuration Guide Firewall Service Board Module v1.0
28
Chapter 3 VPN
VPN (Virtual Private Network) which is defined as public network (usually is defined as Internet) to create a
temporary, safe link, it is a secure and steady tunnel traversing promiscuous public network. It supports SSL,
IPsec, L2TP, and GRE and provides safe and efficient protection for enterprise or government user. The VPN
module provides:
IPsec
L2TP
GRE
SSL VPN
3.1.1
Introduction to IPsec
IP Security (IPsec) refers to a series of protocols defined by the Internet Engineering Task Force (IETF) to
provide high quality, interoperable, and cryptology-based security for IP packets. By means of facilities including
encryption and data origin authentication, it delivers these security services at the IP layer:
Through the IKE (Internet Key Exchange protocol), IPsec provides the auto-negotiate exchange password and
establish and security associate service, to simplify using and management of IPsec.
AH is packet header authentication protocol, mainly providing data source authentication, data integrity and
anti-relay functions; Nonetheless, AH cannot encrypt protected packet.
ESP is the Encapsulating Security Payload protocol, it not only provides the functions except AH protocol
provided (not include IP header integrity verify), but also provides IP packet encryption.
IKE is used to negotiate the password arithmetic of AH and ESP, and automatically establish the security
association and security key exchange.
3.1.2
IPsec VPN configuration
To enter the IPsec VPN configuration page, you choose
Firewall module >VPN > IPsec
, as shown in Figure3-1.