Elements and Options Supported by Cisco Easy VPN Server


Easy VPN is being rolled out in stages, and at this time, it supports some specific protocols and functions but not others. The following section details the protocols and functions that are supported.

Authentication Algorithms

Authentication ensures that you know whom you are communicating with.

graphics/alert_icon.gif

Easy VPN server supports Hash Message Authentication Code with Message Digest 5 (HMAC-MD5) and HMAC-Secure Hash Algorithm 1 (SHA1).


Authentication Methods

When not using Easy VPN, you have the ability to authenticate IPSec peers in one of three ways: preshared keys; Rivest, Shamir, and Adleman (RSA) signatures; and RSA encrypted nonces .

graphics/alert_icon.gif

Easy VPN server supports preshared keys and RSA signatures.


Diffie-Hellman Groups

The Diffie-Hellman (D-H) algorithm provides the ability to establish a shared secret key over an insecure communication channel. There are a number of D-H groups that are identified by number.

graphics/alert_icon.gif

Easy VPN supports D-H groups 2 (1024-bit) and 5 (1536-bit).


IKE Encryption Algorithms

Encryption provides the ability to turn cleartext data into ciphertext , thus rendering the data unreadable until decrypted by authorized devices or users.

graphics/alert_icon.gif

Easy VPN server supports Data Encryption Standard (DES) and Triple DES (3DES) for IKE encryption.


IPSec Encryption Algorithms

IPSec supports an additional encryption algorithm, NULL. However, even though Cisco refers to NULL as an encryption algorithm, it provides no confidentiality whatsoever.

graphics/alert_icon.gif

Easy VPN supports DES, 3DES, and NULL for IPSec encryption.


IPSec Protocols

IPSec has two main protocols, Authentication Header (AH) and Encapsulating Security Payload (ESP). In addition, IPSec also supports the Stacker compression based on the Lempel-Ziv algorithm.

graphics/alert_icon.gif

Easy VPN server supports ESP and IP Payload Compression Protocol with Lempel-Ziv-Stack (IPCOMP-LZS). Compression is implemented using IPCOMP-LZS.


IPSec Modes

The two tunnel types with IPSec are transport mode and tunnel mode.

graphics/alert_icon.gif

Easy VPN server supports tunnel mode only.




CCSP SECUR Exam Cram 2
CCSP SECUR Exam Cram 2 (642-501)
ISBN: B000MU86IQ
EAN: N/A
Year: 2003
Pages: 291
Authors: Raman Sud

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net