由买买提看人间百态

boards

本页内容为未名空间相应帖子的节选和存档,一周内的贴子最多显示50字,超过一周显示500字 访问原贴
Internet版 - Re: more questions on IPsec VPN
相关主题
Re: Questions for IPsec and VPNfastest packet sniffer
求教cisco vpn[转载] 有人在linux下用过ipsec吗?
ZT大陆出差必看 - 超简单DIY跳板(甚么网都可以上了)DSL getting slow
Winodws Server 2008 R2 (转载)AT&T Modem vs. Wireless Gateway.
Re: Question about WPA, help me,please!!PoivY免费电话66分钟(可重复注册)
问个 VPN 的安全性问题Re: 一个关于TCP/UDP的问题
[转载] QoS packet scheduler installation如何计算PLR
[转载] Re: 非法下载电影被报告,版权问题 这个设置怎么该?
相关话题的讨论汇总
话题: ipsec话题: peer话题: vpn话题: packets话题: ike
进入Internet版参与讨论
1 (共1页)
m**t
发帖数: 1292
1

I am just giving perspective from the spec point of view, HUgh actually may
have a lot in the practical world how the products implement the
features
IKE is a peer to peer protocol, taht means with proper policy imposed on
both peers, whenever a peer needs to talk to the other, it needs to
set up the SA first, so for the responder(the one who receives the packets),
the SA should have been in place since the initiator was supposed to
do the IKE whenever the initiator sees the outbound packets
h**h
发帖数: 132
2
Most of my experiences are w/ Cisco, but for network administrator,
we only know a few outmost configs, and a very limited understanding
of the inner theory:-(
For speed of IPSec, there are two different things
1> for interactive traffic, such as telnet, it may be slow, not only
because the buffer of packets, but also protocol overhead
2> Encryption overhead, it depends on whether it is a hardware based
or software based, many of cisco's devices are utilizing ASIC and offload
encryption from pro
h**h
发帖数: 132
3
I guess so, at least that's what we do. both need to configure
for the particular peers, some steps but not limited to these
1> make sure both are using the same encryption, transform-set
authentication, using correct trigger for interesting traffic and etc.
2> generate keys (say RSA-Encrypted nonces) if none
3> obtain pubkey and distribute to the other (manual process)
4> configure pubkey for remote peer
5> test it out!!!
again, IPSec only works for peer session for particular interesting
packe
1 (共1页)
进入Internet版参与讨论
相关主题
这个设置怎么该?Re: Question about WPA, help me,please!!
[转载] about udp programming问个 VPN 的安全性问题
急问如何知道自己的浏览器是否128-bit security encryption?[转载] QoS packet scheduler installation
Re: 急问如何知道自己的浏览器是否128-bit security encryption?[转载] Re: 非法下载电影被报告,版权问题
Re: Questions for IPsec and VPNfastest packet sniffer
求教cisco vpn[转载] 有人在linux下用过ipsec吗?
ZT大陆出差必看 - 超简单DIY跳板(甚么网都可以上了)DSL getting slow
Winodws Server 2008 R2 (转载)AT&T Modem vs. Wireless Gateway.
相关话题的讨论汇总
话题: ipsec话题: peer话题: vpn话题: packets话题: ike