25.02.2013 Views

TCP/IP Tutorial and Technical Overview - IBM Redbooks

TCP/IP Tutorial and Technical Overview - IBM Redbooks

TCP/IP Tutorial and Technical Overview - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Note: ESP authentication data was not present in early implementations of<br />

the <strong>IBM</strong> firewall.<br />

<strong>IP</strong> Hdr ESP Inner Payload<br />

ESP<br />

AH<br />

Hdr <strong>IP</strong> Hdr<br />

Trl<br />

Figure 22-34 Combined AH-ESP tunnel<br />

Case 3: End-to-end security with VPN support<br />

This case is a combination of cases 1 <strong>and</strong> 2 <strong>and</strong> does not raise new <strong>IP</strong>Sec<br />

requirements for the machines involved (see Figure 22-35). The big difference<br />

from case 2 is that now the hosts are also required to support <strong>IP</strong>Sec.<br />

H1 intranet G1 Internet/<br />

intranet<br />

G2 intranet<br />

H2<br />

Connection <strong>IP</strong>Sec tunnels<br />

Figure 22-35 End-to-end security with VPN support<br />

In a typical setup, the gateways use AH in tunnel mode, while the hosts use ESP<br />

in transport mode. An enhanced security version might use a combined AH-ESP<br />

tunnel between the gateways. In this way, the ultimate destination addresses are<br />

encrypted; the whole packet traveling the Internet would be authenticated <strong>and</strong><br />

the carried data double encrypted. This is the only case when three stages of<br />

<strong>IP</strong>Sec processing might be useful, however, at a cost—the performance impact<br />

is considerable.<br />

AH tunneling of ESP transport<br />

Let us look in more detail at the common combination of using AH tunneling to<br />

protect ESP traffic in transport mode.<br />

Chapter 22. <strong>TCP</strong>/<strong>IP</strong> security 827

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!