Avaya BCM50 Guia de Configuração Página 527

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 568
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 526
Appendix A VPN overview 527
Networking Configuration Guide
IPSec
Nortel and other third-party vendors support the IPsec tunneling protocol. IPsec is an emerging
standard that offers a strong level of encryption (DES and Triple DES), integrity protection (MD5
and SHA), and the IETF-commended Internet Security Association & Key Management Protocol
(ISAKMP) and Oakley Key Determination Protocols.
Encryption
All of the following encryption methods ensure that the packets have come from the original
source at the secure end of the tunnel. Note that some of the encryption types will not appear on
some non-US models that are restricted by US Domestic export laws.
Table 119 shows a comparison of the security provided by the available encryption and
authentication methods.
Table 119 Comparing Encryption and Authentication Methods
Method
(strongest to weakest)
Encryption of IP
Packet Payload
Authentication
of IP Packet
Payload
Authentication
of Entire IP
Packet
ESP Triple DES SHA1 Yes Yes No
ESP Triple DES MD5 Yes Yes No
ESP 56-bit DES SHA1 Yes Yes No
ESP 56-bit DES MD5 Yes Yes No
ESP 40-bit DES SHA1 Yes Yes No
ESP 40-bit DES MD5 Yes Yes No
AH HMAC SHA1 No No Yes
AH HMAC MD5 No No Yes
Note: Using higher-level encryption, such as Triple DES, requires more system resources
and increases packet latency. You must consider this when designing your overall
network.
Note: If two devices have different encryption settings, the two devices will negotiate
downward until they agree on a compatible encryption capability. For example, if Switch
A attempts to negotiate Triple DES encryption with Switch B that is using 56-bit DES,
then the Switch B will reject Triple DES encryption in favor of the 56-bit DES.
Each of the systems must have at least one encryption setting in common. If they do not, a
tunnel is not negotiated. In the example above, both systems must have 56-bit DES
enabled.
Vista de página 526
1 2 ... 522 523 524 525 526 527 528 529 530 531 532 ... 567 568

Comentários a estes Manuais

Sem comentários