Summary

IPsec is the standard method of providing cryptographic protection for IP packets. The two protocols used for IP packet protection are AH and ESP. AH provides data origin authentication, data integrity, and replay protection for the entire IP packet, except for the fields in the IP header that are allowed to change in transit. ESP provides data origin authentication, data integrity, data confidentiality, and replay protection for the ESP-encapsulated payload.

To negotiate SAs for sending secure traffic, IPsec uses IKE, a combination of ISAKMP and the Oakley Key Determination Protocol. ISAKMP messages contain many types of payloads to exchange information during SA negotiation. Main mode negotiation determines the ISAKMP SA, which is used ...

Get Windows Server® 2008 TCP/IP Protocols and Services now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.