25.02.2013 Views

TCP/IP Tutorial and Technical Overview - IBM Redbooks

TCP/IP Tutorial and Technical Overview - IBM Redbooks

TCP/IP Tutorial and Technical Overview - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IKE phase 2, message 1<br />

Message 1 of a Quick Mode Exchange allows Host-A to authenticate itself, to<br />

select a nonce, to propose Security Associations to Host-B, to execute an<br />

exchange of public Diffie-Hellman values, <strong>and</strong> to indicate if it is acting on its own<br />

behalf or as a proxy negotiator for another entity. An overview of the format of<br />

message 1 is shown in Figure 22-41.<br />

Note: Inclusion of a Key Exchange field is optional. However, when Perfect<br />

Forward Secrecy is used, it must be present.<br />

<strong>IP</strong><br />

Header<br />

UDP<br />

Header<br />

ISAKMP<br />

Header<br />

Hash SA Proposal<br />

#1<br />

Transform<br />

#1<br />

Hash-1,SA(ESP & AH),gx, Nj<br />

... Proposal<br />

#n<br />

Transform<br />

#n<br />

Host A Hash-2,SA(ESP & AH),gy, Nr<br />

Host B<br />

Hash-3<br />

Figure 22-41 Message 1 of an ISAKMP phase 2 Quick Mode Exchange<br />

N K<br />

E<br />

Because we assumed that Host-A <strong>and</strong> Host-B are each acting on their own<br />

behalf, the user identity fields illustrated in Figure 22-41 will not be present. The<br />

message will consist of:<br />

ISAKMP header The ISAKMP header indicates an exchange type of<br />

Quick Mode, includes a non-zero Message ID chosen<br />

by Host-A, includes the initiator <strong>and</strong> responder cookie<br />

values chosen in phase 1 (that is, Cookie-A <strong>and</strong><br />

Cookie-B), <strong>and</strong> turns on the encryption flag to indicate<br />

that the payloads of the ISAKMP message are<br />

encrypted according to the algorithm <strong>and</strong> key<br />

negotiated during phase 1.<br />

IDs<br />

Chapter 22. <strong>TCP</strong>/<strong>IP</strong> security 841

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!