beautypg.com

Encapsulating security payload, Basic ipsec configurations, Endpoint to endpoint – Brocade Web Tools Administrators Guide (Supporting Fabric OS v7.3.0) User Manual

Page 225

background image

FIGURE 44 AH header in transport mode and tunnel mode

Encapsulating Security Payload

ESP provides authentication, and also provides privacy by encrypting the IP datagram. The use of an
ESP header is similar to the use of the AH header. A hash algorithm is used to calculate an
authentication value, the authentication value is sent in an IP datagram, and the same hash algorithm is
used by the receiver to verify the authentication value. ESP can be used in either transport mode or
tunnel mode, as shown in the following figure.

FIGURE 45 ESP header in transport mode and tunnel mode

Basic IPsec configurations

There are three basic configurations for IPsec use:

• Endpoint to Endpoint
• Gateway to Gateway
• Endpoint to Gateway

Endpoint to Endpoint

In an endpoint to endpoint configuration, both endpoints implement IPsec. Transport mode is commonly
used in endpoint to endpoint configurations, and only a single pair of addresses is used. Typically, this

Encapsulating Security Payload

Web Tools Administrator's Guide

225

53-1003169-01