Module 3 NS
Module 3 NS
Module 3 NS
INTRODUCTION
• IP security (IPSec) is a collection of protocols
designed to provide security for a packet
IP Security Scenario
IPsec Documents
The documents can be categorized into the
following groups.
• Architecture
• Authentication Header (AH)
• Encapsulating Security Payload (ESP)
• Internet Key Exchange (IKE)
• Cryptographic algorithms
IPsec Services
IPSec services are listed below:
• Access control
• Connectionless integrity
• Data origin authentication
• Rejection of replayed packets (a form of partial
sequence integrity
• Confidentiality (encryption)
• Limited traffic flow confidentiality
Modes of Operation
TUNNEL MODE
Transport and tunnel mode
Transport and tunnel mode functionality
Transport and Tunnel Mode ESP
Transport Mode ESP
•
Security Associations
A security association is uniquely identified
by three parameters.
• Security Parameters Index (SPI)
• IP Destination Address
• Public-key encryption
• Symmetric-key encryption
Header and Payload Formats
• IKE HEADER FORMAT
IKE PAYLOAD TYPES
SA payload
These elements are formatted as substructures
within the payload as follows.
• ✓ Proposal
• ✓ Transform
• ✓ Attribute
Key Exchange payload
• Identification payload
• Certificate payload
• Certificate Request payload
• Authentication payload
• Nonce payload
• Delete payload
• Vendor ID payload
• Traffic Selector payload
• Encrypted payload
• Configuration payload
• Extensible Authentication Protocol (EAP)