
Getting Started with IPsec
304111-A Rev 00
2-9
Security Protocols
IPsec uses the following encryption services:
• Data Encryption Standard (DES)
• Message Digest 5 (MD5)
ESP uses the cipher block chaining (CBC) mode of the DES encryption
algorithm. CBC is considered the most secure mode of DES. A 56-bit or 40-bit
number that you generate, known as a key, controls encryption and decryption.
Key management is manual.
DES is available in two encryption strengths:
• 56-bit DES keys (recommended)
• 40-bit DES keys
Both sides of an SA must use the same encryption strength. Normally, you should
use the stronger 56-bit DES key. However, if you are communicating with a
security gateway that is limited to a 40-bit DES key, you must use the 40-bit key.
When ESP protection is used in tunnel mode, an “outer” IP header specifies the
IPsec processing destination, and an “inner” IP header specifies the (apparently)
ultimate destination for the packet. The security protocol header appears after the
outer IP header and before the inner one. Only the tunneled packet is protected,
not the outer header.
Kommentare zu diesen Handbüchern