12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

92 Understanding VPN tunnelsIPsec standardEncapsulation modesPackets that are encapsulated have their contents hidden from public view, and are restored to theiroriginal state only when the packet arrives at its intended destination. IPsec supports the encapsulation, orprotection, of packets through either transport mode or tunnel mode. The encapsulation mode you selectdetermines the rest of the policy information you must enter.Transport modeTransport mode is designed for host-to-host connections only, where the destination address is an endnode, and not a gateway that encrypts and decrypts on behalf of an end node. This restriction is presentbecause there is no inner IP header in a transport mode packet. Once the destination system receives thepacket, and strips off the IPsec header, only the original (outer) header is present, and its destinationaddress is the system it’s on.Transport mode is not very flexible; tunnel mode is often used instead.Tunnel modeTunnel mode is designed for gateway-to-gateway or host-to-gateway connections where the destinationaddress is the decryption engine, but not necessarily the packet’s final destination. Tunnel mode also workswith host-to-host connections, but using tunnel mode for host-to-host connections does not offer anadvantage over transport mode. In fact, transport mode is better because it does not add an extra IP headerto the packet.An IPsec tunnel mode packet is encapsulated with an authentication header (AH) or encapsulating securityprotocol (ESP) header and an additional IP header. This creates two IP headers, an inside or protectedheader that was created by the source host and an outside or clear-text header created by the hostproviding the packet security services (encryption). The IP addresses in the outer IP header define theendpoints of the tunnel, and the IP addresses in the inner IP header mark the true source and finaldestination for the packet.A common use of tunnel mode is to support VPN networks where connections are secured by means ofIPsec.Note: IPsec tunnel mode does not work directly with a gateway that employs network address porttranslation (NAPT), unless that gateway can parse the security parameter index (SPI) for the portinformation. Symantec security gateways work properly with NAPT, but third-party security gateways maynot.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!