418
CN4093 Application Guide for N/OS 8.4
IPsec Protocols
The
Enterprise
NOS
implementation
of
IPsec
supports
the
following
protocols:
Authentication
Header
(AH)
AHs
provide
connectionless
integrity
and
data
origin
authentication
for
IP
packets,
and
provide
protection
against
replay
attacks.
In
IPv6,
the
AH
protects
the
AH
itself,
the
Destination
Options
extension
header
after
the
AH,
and
the
IP
payload.
It
also
protects
the
fixed
IPv6
header
and
all
extension
headers
before
the
AH,
except
for
the
mutable
fields
DSCP,
ECN,
Flow
Label,
and
Hop
Limit.
AH
is
defined
in
RFC
4302.
Encapsulating
Security
Payload
(ESP)
ESPs
provide
confidentiality,
data
origin
authentication,
integrity,
an
anti
‐
replay
service
(a
form
of
partial
sequence
integrity),
and
some
traffic
flow
confidentiality.
ESPs
may
be
applied
alone
or
in
combination
with
an
AH.
ESP
is
defined
in
RFC
4303.
Internet
Key
Exchange
Version
2
(IKEv2)
IKEv2
is
used
for
mutual
authentication
between
two
network
elements.
An
IKE
establishes
a
security
association
(SA)
that
includes
shared
secret
information
to
efficiently
establish
SAs
for
ESPs
and
AHs,
and
a
set
of
cryptographic
algorithms
to
be
used
by
the
SAs
to
protect
the
associated
traffic.
IKEv2
is
defined
in
RFC
4306.
Using
IKEv2
as
the
foundation,
IPsec
supports
ESP
for
encryption
and/or
authentication,
and/or
AH
for
authentication
of
the
remote
partner.
Both
ESP
and
AH
rely
on
security
associations.
A
security
association
(SA)
is
the
bundle
of
algorithms
and
parameters
(such
as
keys)
that
encrypt
and
authenticate
a
particular
flow
in
one
direction.
Summary of Contents for Flex System Fabric CN4093
Page 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Page 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Page 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Page 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Page 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Page 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Page 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Page 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Page 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Page 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Page 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Page 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Page 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Page 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Page 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Page 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Page 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Page 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Page 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Page 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Page 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Page 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Page 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Page 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Page 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Page 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Page 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Page 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Page 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Page 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Page 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Page 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Page 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Page 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Page 633: ......
Page 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...