Netgear FVM318 FVM318 Reference Manual - Page 148
Negotiating the SA - the Internet Key Exchange IKE
View all Netgear FVM318 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 148 highlights
Reference Manual for the Model FVM318 Cable/DSL ProSafe Wireless VPN Security Firewall • Exchange keys • Keep track of the agreements Negotiating the SA - the Internet Key Exchange (IKE) IKE provides a way to: • Ensure that the key exchange and the IPSec communication occurs only between authenticated parties; • Negotiate the protocols, algorithms and keys to be used between the two IPSec hosts • Securely update and renegotiate SAs when they have expired. IKE functions in two phases: 1. Phase 1. The peers establish a secure channel. After Phase 1, all IKE packets are encrypted. 2. Phase 2. The peers negotiate a general purpose SA. IKE provides three modes of key exchange and setting up of SAs. Two of the modes are used in the first phase and one in the second. Authentication: Phase 1 Main mode or Aggressive mode can be chosen in the first phase. • Main mode. This mode accomplishes the first phase by establishing a secure channel before sending a user identity. Main mode secures an IKE SA in three two-way exchanges between the initiator and the responder. a. Both agree on basic algorithms and hashes. b. Both exchange Diffie-Hellman public keys and pass nonces. Nonce is a cryptographic term for a fresh random number that is used only once. c. Both parties verify each other's identity. This exchange is already encrypted. • Aggressive mode. Unlike Main mode, it does not protect identities because it establishes the secure channel after the information has been exchanged. Aggressive mode establishes a connection with two exchanges. Only one of these is a round-trip exchange. a. The initiator generates a Diffie-Hellman public value, sending it with the nonce. B-22 Network, Routing, Firewall, and Wireless Basics
-
1
-
2
-
3
-
4
-
5
-
6
-
7
-
8
-
9
-
10
-
11
-
12
-
13
-
14
-
15
-
16
-
17
-
18
-
19
-
20
-
21
-
22
-
23
-
24
-
25
-
26
-
27
-
28
-
29
-
30
-
31
-
32
-
33
-
34
-
35
-
36
-
37
-
38
-
39
-
40
-
41
-
42
-
43
-
44
-
45
-
46
-
47
-
48
-
49
-
50
-
51
-
52
-
53
-
54
-
55
-
56
-
57
-
58
-
59
-
60
-
61
-
62
-
63
-
64
-
65
-
66
-
67
-
68
-
69
-
70
-
71
-
72
-
73
-
74
-
75
-
76
-
77
-
78
-
79
-
80
-
81
-
82
-
83
-
84
-
85
-
86
-
87
-
88
-
89
-
90
-
91
-
92
-
93
-
94
-
95
-
96
-
97
-
98
-
99
-
100
-
101
-
102
-
103
-
104
-
105
-
106
-
107
-
108
-
109
-
110
-
111
-
112
-
113
-
114
-
115
-
116
-
117
-
118
-
119
-
120
-
121
-
122
-
123
-
124
-
125
-
126
-
127
-
128
-
129
-
130
-
131
-
132
-
133
-
134
-
135
-
136
-
137
-
138
-
139
-
140
-
141
-
142
-
143
-
144
-
145
-
146
-
147
-
148
-
149
-
150
-
151
-
152
-
153
-
154
-
155
-
156
-
157
-
158
-
159
-
160
-
161
-
162
-
163
-
164
-
165
-
166
-
167
-
168
-
169
-
170
-
171
-
172
-
173
-
174
-
175
-
176
-
177
-
178
-
179
-
180
-
181
-
182
-
183
-
184