Elements and Options Not Supported by Cisco Easy VPN Server


It should be evident which protocols Easy VPN does not support through your knowledge of IPSec and by reading Chapter 8, "Understanding IPSec VPNs on Cisco Routers." If you have read the previous section and do not know the other IPSec protocols, you really need to re-read IPSec Chapter 8.

Authentication Types

An additional authentication method is Digital Signature Standard (DSS).

graphics/alert_icon.gif

Easy VPN server does not support DSS.


D-H Groups

The D-H group identifiers are 1, 2, 5, and 7.

graphics/alert_icon.gif

Easy VPN Server does not support D-H group 1.


IPSec Protocols

The two main IPSec protocols are AH and ESP.

graphics/alert_icon.gif

Easy VPN server does not support AH.


IPSec Modes

Transport mode and tunnel mode provide different levels of traffic security. Tunnel mode provides some additional benefits.

graphics/alert_icon.gif

Easy VPN Server does not support transport mode.


Perfect Forward Secrecy

The shared secret key used with symmetrical security algorithm is established during IKE negotiations using the D-H protocol. Through the use of Perfect Forward Secrecy (PFS), the shared secret key can be renegotiated in the IPSec tunnel.

graphics/alert_icon.gif

Easy VPN Server does not support PFS.


Manual Keys

The three methods you use to authenticate an IPSec peer are preshared keys, RSA signatures, and RSA encrypted nonces. Manual keys are established when you decide to use RSA encrypted nonces for authentication.

graphics/alert_icon.gif

Easy VPN Server does not support manual keys (RSA encrypted nonces).




CCSP SECUR Exam Cram 2
CCSP SECUR Exam Cram 2 (642-501)
ISBN: B000MU86IQ
EAN: N/A
Year: 2003
Pages: 291
Authors: Raman Sud

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net