|
|
|
|
|
|
|
Security (IPSec) Encryption-CHS版11 |
|
|
|
|
thenticated header. The actual user datastream is not encrypted. For datastream encryption, you need ESP. If you use only AH and see cleartext going across the network, do not be surprised. You if you use AH, also use ESP. Note that ESP can perform authentication also. Therefore, you can use a transform combination such as esp-des and esp-sha-hmac.
ah-rfc1828 and esp-rfc1829 are obsolete transforms included for backwards compatibility with older IPSec implementations. If the peer does not support newer transforms, try these instead.
SHA is slower and more secure than MD5, whereas MD5 is faster and less secure that SHA. In some communities, the comfort level with MD5 is very low.
When in doubt, use tunnel mode. Tunnel mode is the default and it can be used in transport mode, as well as for its VPN capabilities.
For classic crypto users who upgrade t 页码:[1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] 第11页、共13页 |
|
|
|
|
设为首页 | 加入收藏 | 广告服务 | 友情链接 | 版权申明
Copyriht 2007 - 2008 © 科普之友 All right reserved |