User's Manual

Chapter 16 IPSec VPN 121
16.3 Technical Reference
This section provides some technical background information about the topics covered in this
section.
16.3.1 IPSec Architecture
The overall IPSec architecture is shown as follows.
Figure 78 IPSe
c Architecture
IPSec Algorithms
The ESP
(Encapsulating Security Payload) Protocol (RFC 2406) and AH (Authentication Header)
protocol (RFC 2402) describe the packet formats and the default standards for packet structure
(including implementation algorithms).
The Encryption Algorithm describes the use of encryption techniques
such as DES (Data Encryption
Standard) and Triple DES algorithms.
The Authentication Algorithms, HMAC-MD5 (RFC 2403) and HMAC-SHA-1 (RFC 2404, provide an
au
thentication mechanism for the AH and ESP protocols.
Key Management
Key management allows you to determine whether t
o use IKE (ISAKMP) or manual key configuration
in order to set up a VPN.