Required Protocols for IPSec


When you ping between two IPSec routers, you are verifying you have connectivity between these routers and that at a minimum, Internet Control Message Protocol (ICMP) echo packets are not filtered. But, because of ever-increasing security concerns in corporate networks, only traffic that is required into the corporate network is permitted, and all other types of traffic are filtered.

When running IPSec in your environment, you must be sure that IPSec traffic itself is not filtered. To verify this fact, you must make sure the following protocols are not filtered between the two IPSec peers.

IKE Phase 1 traffic:

UDP port 500

ESP traffic:

IP protocol 50

AH traffic:

IP protocol 51



CCSP SECUR Exam Cram 2
CCSP SECUR Exam Cram 2 (642-501)
ISBN: B000MU86IQ
EAN: N/A
Year: 2003
Pages: 291
Authors: Raman Sud

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net