思科网络安全-第八部分.ppt

* * * First packet - The initiator packages everything needed for the SA negotiation in the first message, including its DH public key. Second packet - The recipient responds with the acceptable parameters, authentication information, and its DH public key. 上面提到的两个DH public key是指在DH交换信息过程中的YA和YB 。 * * * * * * * 双方的优先级可以不同,系统会自动协商两者之间匹配的一对。数值越低优先级越高。 双方的密钥生存周期若不一致,则以短的一方为准。 Notice however, that policy numbers are only locally significant and do not have to match between IPsec peers. * * * * * * * * * PFS (Perfect Forwarding Secrecy) enhances security by using different security key for th

文档评论(0)

1亿VIP精品文档

相关文档