Escolar Documentos
Profissional Documentos
Cultura Documentos
Agenda
Introductory Information on IPSec VPN
Why Diffie-Hellman Algorithm?
IKE SA in Main Mode
IPSec SA in Quick Mode
Some Troubleshooting Tips
Agenda
Introductory Information on IPSec VPN
Why Diffie-Hellman Algorithm?
IKE SA in Main Mode
IPSec SA in Quick Mode
Some Troubleshooting Tips
Agenda
Introductory Information on IPSec VPN
Why Diffie-Hellman Algorithm?
IKE SA in Main Mode
IPSec SA in Quick Mode
Some Troubleshooting Tips
Performance!
Examples:
30 mod 16 = 14
114 mod 100 = 14
8 mod 3 = 2
Isnt that simple?
Diffie-Hellman:
Initiator takes a prime number p and an
integer a with 1 < a < p and a secret
integer x with:
X = ax mod p
X, a, p: public parameters,
x: secret parameter.
Hence Kx = Ky
Agenda
Introductory Information on IPSec VPN
Why Diffie-Hellman Algorithm?
IKE SA in Main Mode
IPSec SA in Quick Mode
Some Troubleshooting Tips
Initiator
Packet Number 1:
Responder
AES-128!
SHA-1!
DH-Group 14!
Preshared Key!
Initiator
Packet Number 1:
Packet Number 2:
Responder
Then, the Initiator sends the public DiffieHellman Parameters and a random
number, which is called Nonce:
Initiator
Packet Number 3:
Responder
Initiator
Packet Number 3:
Packet Number 4:
Responder
Initiator
Packet Number 5:
Packet Number 6:
Responder
Agenda
Introductory Information on IPSec VPN
Why Diffie-Hellman Algorithm?
IKE SA in Main Mode
IPSec SA in Quick Mode
Some Troubleshooting Tips
Payload Encryption
Data Integrity Checking
Replay Protection
Why is it necessary to
agree upon the
Encryption Algorithm
Hash Algorithm
Eventually DH-Group
again?
Agenda
Introductory Information on IPSec VPN
Why Diffie-Hellman Algorithm?
IKE SA in Main Mode
IPSec SA in Quick Mode
Some Troubleshooting Tips
Any solution?
Any Questions?