Chapter 2. IPsec Fundamentals


Internet Protocol Security (IPsec), as defined in RFC 2401, provides a means by which to ensure the authenticity, integrity, and confidentiality of data at the network layer of the Open System Interconnection (OSI) stack. IPsec is a suite of protocols that define standards for four key elements needed in defining a comprehensively robust Virtual Private Network (VPN) enabler:

  • Security Protocols

  • Key Exchange Mechanisms

  • Algorithms Required for Encryption and Secure Key Exchange

  • SA Definitions and Maintenance

In this chapter, we will introduce the cryptographic components and concepts necessary to understand how IPsec delivers on promises of secure transmittal of data across untrusted media. In order to understand the encryption algorithms and security protocols used by IPsec, one must first understand how encrypted messages are formed. In this chapter, we will discuss the basic elements of encryption that will clarify the cryptographic mechanisms used within the IPsec protocol suite. Additionally, we will explore IPsec's establishment of secure data tunnels, IPsec VPNs, with other peers. IPsec employs the Internet Key Exchange (IKE) protocol to exchange keys. This chapter will cover the critical importance of IKE within the IPsec protocol suite and its role in establishing IPsec Security Associations (SAs).

Note

The IKE protocol is used within the Internet Security Association and Key Management Protocol (ISAKMP) framework. However, throughout the course of this text, especially when describing SA establishment, the terms IKE and ISAKMP will be used interchangeably.





IPsec Virtual Private Network Fundamentals
IPSec Virtual Private Network Fundamentals
ISBN: 1587052075
EAN: 2147483647
Year: N/A
Pages: 113

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net