IPSEC Flashcards
What does AH stand for
Authentication Header
What does ESP stand for
Encapsulating Security payload
What does IKE stand for
Internet Key Exchange
What does AH do
Auth, integrity, replay
What does ESP do
auth, confidentiality
Two modes of IPSEC
tunnel, transport modes
What does IKE phase 1 do
IKE SA is negotiated (Security Association)
What does IKE phase 2 do
IPSEC SA is negotiated
What does the IKE policy contain
encryption(aes), hash(sha), authentication(pre-share), DH, lifetime
What creates the IPSEC SA
ipsec transform-set command
What does the transform set do
Lets you pick a set of security parameters for IPSEC (esp-sha-hmac)
What does Crypto map/ACL do
Defines “interesting traffic” that will be protected by encryption
Which direction is the crypto ACL applied
neither, it works in both directions