25.02.2013 Views

TCP/IP Tutorial and Technical Overview - IBM Redbooks

TCP/IP Tutorial and Technical Overview - IBM Redbooks

TCP/IP Tutorial and Technical Overview - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Figure 8-21 shows the cooperation of the DS network elements with the LDAP<br />

server.<br />

Boundary Components<br />

LDAP Client<br />

hosts<br />

proxies<br />

routers<br />

Figure 8-21 Administration of DS components with LDAP<br />

Using Differentiated Services with <strong>IP</strong>Sec<br />

The <strong>IP</strong>Sec protocol (described in 22.4.3, “Encapsulating Security Payload (ESP)”<br />

on page 817) does not use the DS field in an <strong>IP</strong> header for its cryptographic<br />

calculations. Therefore, modification of the DS field by a network node has no<br />

effect on <strong>IP</strong>Sec's end-to-end security, because it cannot cause any <strong>IP</strong>Sec<br />

integrity check to fail. This makes it possible to use <strong>IP</strong>Sec-secured packets in DS<br />

networks.<br />

<strong>IP</strong>Sec's tunnel mode provides security for the encapsulated <strong>IP</strong> header's DS field.<br />

A tunnel mode <strong>IP</strong>Sec packet contains an outer header that is supplied by the<br />

tunnel start point <strong>and</strong> an encapsulated inner header that is supplied by the host<br />

that originally sent the packet.<br />

324 <strong>TCP</strong>/<strong>IP</strong> <strong>Tutorial</strong> <strong>and</strong> <strong>Technical</strong> <strong>Overview</strong><br />

Router<br />

LDAP= Lightweight Directory Access Protocol<br />

Policy<br />

Database<br />

LDAP Server<br />

Router<br />

<strong>IP</strong><br />

Interior Components<br />

Router<br />

Boundary Components<br />

LDAP Client<br />

hosts<br />

proxies<br />

routers

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!