5.1

Table Of Contents
n
Diffie-Hellman (DH) key exchange is a cryptographic protocol that allows two parties that have no prior
knowledge of each other to jointly establish a shared secret key over an insecure communications channel.
VSE supports DH group 2 (1024 bits) and group 5 (1536 bits).
IKE Phase 1 and Phase 2
IKE is a standard method used to arrange secure, authenticated communications.
Phase 1 Parameters
Phase 1 sets up mutual authentication of the peers, negotiates cryptographic parameters, and creates session
keys. The Phase 1 parameters used by the vShield Edge are:
n
Main mode
n
TripleDES / AES [Configurable]
n
SHA-1
n
MODP group 2 (1024 bits)
n
pre-shared secret [Configurable]
n
SA lifetime of 28800 seconds (eight hours) with no kbytes rekeying
n
ISAKMP aggressive mode disabled
Phase 2 Parameters
IKE Phase 2 negotiates an IPSec tunnel by creating keying material for the IPSec tunnel to use (either by using
the IKE phase one keys as a base or by performing a new key exchange). The IKE Phase 2 parameters supported
by vShield Edge are:
n
TripleDES / AES [Will match the Phase 1 setting]
n
SHA-1
n
ESP tunnel mode
n
MODP group 2 (1024 bits)
n
Perfect forward secrecy for rekeying
n
SA lifetime of 3600 seconds (one hour) with no kbytes rekeying
n
Selectors for all IP protocols, all ports, between the two networks, using IPv4 subnets
Transaction Modes Samples
vShield Edge supports Main Mode for Phase 1 and Quick Mode for Phase 2.
vShield Edge proposes a policy that requires PSK, 3DES/AES128, sha1, and DH Group 2/5. The peer must
accept this policy; otherwise, the negotiation phase fails.
Phase 1: Main Mode Transactions
This example shows an exchange of Phase 1 negotiation initiated from a vShield Edge to a Cisco device.
The following transactions occur in sequence between the vShield Edge and a Cisco VPN device in Main Mode.
1 vShield Edge to Cisco
n
proposal: encrypt 3des-cbc, sha, psk, group5(group2)
n
DPD enabled
2 Cisco to vShield Edge
n
contains proposal chosen by Cisco
Chapter 9 vShield Edge Management
VMware, Inc. 85