Ike operation, Functions of ike in ipsec – H3C Technologies H3C SecPath F1000-E User Manual
Page 134
122
IKE operation
IKE negotiates keys and establishes SAs for IPsec in two phases:
1.
Phase 1—The two peers establish an ISAKMP SA, a secure, authenticated channel for
communication. In this phase, two modes are available: main mode and aggressive mode.
2.
Phase 2—Using the ISAKMP SA established in phase 1, the two peers negotiate to establish IPsec
SAs.
Figure 80 IKE exchange process in main mode
As shown in
, the main mode of IKE negotiation in phase 1 involves three pairs of messages:
•
SA exchange, used for negotiating the security policy.
•
Key exchange, used for exchanging the Diffie-Hellman public value and other values like the
random number. Key data is generated in this stage.
•
ID and authentication data exchange, used for authentication of identity and exchanged data in
phase 1.
The main difference between main mode and aggressive mode is that aggressive mode does not provide
identity protection and only exchanges the above three messages. Aggressive mode exchanges less
information and features higher negotiation speed; it applies to scenarios where the requirement for
identity protection is lower. For scenarios with higher requirement for identity protection, use the main
mode.
Functions of IKE in IPsec
IKE provides the following functions for IPsec:
•
Automatically negotiates IPsec parameters such as the keys, reducing the manual configuration
complexity.
•
Performs DH exchange whenever establishing an SA, making sure that each SA has a key
independent of any other keys.
•
Automatically negotiates SAs when the sequence number in the AH or ESP header overflows,
making sure that IPsec provides the anti-replay service normally by using the sequence number.
- H3C SecPath F5000-A5 Firewall H3C SecPath F1000-A-EI H3C SecPath F1000-E-SI H3C SecPath F1000-S-AI H3C SecPath F5000-S Firewall H3C SecPath F5000-C Firewall H3C SecPath F100-C-SI H3C SecPath F1000-C-SI H3C SecPath F100-A-SI H3C SecBlade FW Cards H3C SecBlade FW Enhanced Cards H3C SecPath U200-A U200-M U200-S H3C SecPath U200-CA U200-CM U200-CS