21
Internet Key Exchange
IKE protocol is that several important issue in secure communication sets. Authentication points, such as key exchange, symmetric. This protocol, the Assembly, the security (SA) have created and SAD or base Assembly, Security Association data base ). IKE protocol that generally requires user space is tremendous and the operating system doesn't implement. Protocol, IKE, port number, UDP/500. IKE consists of two stages. The first stage, the same forming Assembly, the Security Key Management (Internet Security Association and key) or (ISAKMP SA). Privacy [edit] to negotiate and set the IPSec SA is used. Authentication the first stage points, such as usually based on keys ago subscription (Per shared Keys ), the arrow keys, RSA certificates X509 arise. The first stage of The support is appreciated. The main mode (main mode) and aggressive mode (aggressive mode) between these two points, such as the authentication and ISAKMP SA will set. In aggressive mode, only half the number of messages in this case are covered. Anyway, this is a bug can be considered, because this mode can not be from the identity of the points, peer support, protect, and from this the direction that this state having advance key shared (PSK) APT attacks among the way (man-in-the-middle) would be. On the other side, the only purpose of the offensive is the same. In the main mode, not key preconditions different can't support points, peer-to-peer will also not recognize. In aggressive mode, that of protecting the identity of individuals / support points does not, and the identity of the users of the endpoints of such a transparent transfer. So points such as every thing will know before the authentication of the identity about the fit and the keys to the preconditions be applied. In the second stage of the protocol, IKE, is SA, the proposed exchange are and the agreement on the base ISAKMP SA for SA will be done. ISAKMP SA authentication for the protection of the bronchi, between the way the preparation of The sees. The second step of the quick mode uses. Usually two points, such as the SAKMP SA together, negotiate and agree that both sides are usually on several negotiation (at least 2) indirectly, agreed....