IKE ID & Proxy ID

There are 2 IDs in an IKE exchange. The ID in phase 1 is used for authentication of the remote VPN gateway (i.e., to identify and verify the peer gateway). This ID can be one of many types. Right now Netscreen supports:
ID_IPV4_ADDR (e.g., 216.59.109.152)
ID_FQDN (e.g., www.juniper.net)
ID_USER_FQDN (e.g., dklein@juniper.net)
ID_DER_ASN1_DN ( Distinguished Name in Certificate)

There is another ID used in phase 2 (Quick Mode). This ID is also referred to as "proxy id". This ID (proxy id) is retrieved from the pre-configured policy and is used to make sure both gateways have the same policy (i.e., firewall filter). This ID can be one of:
ID_IPV4-ADDR
ID_IPV4_SUBNET
ID_IPV4_RANGE (which NetScreen does not support now)

No other ID type can be used in the proxy id.


The ISAKMP id modes are defined in RFC 2407 section 4.6.2.1.

---excerpt from RFC 2407 ------->

4.6.2.1 Identification Type Values
The following table lists the assigned values for the Identification Type field found in the Identification Payload.

ID Type Value


RESERVED 0
ID_IPV4_ADDR 1
ID_FQDN 2
ID_USER_FQDN 3
ID_IPV4_ADDR_SUBNET 4
ID_IPV6_ADDR 5
ID_IPV6_ADDR_SUBNET 6
ID_IPV4_ADDR_RANGE 7
ID_IPV6_ADDR_RANGE 8
ID_DER_ASN1_DN 9
ID_DER_ASN1_GN 10
ID_KEY_ID 11

For types where the ID entity is variable length, the size of the ID entity is computed from size in the ID payload header. When an IKE exchange is authenticated using certificates (of any format), any ID's used for input to local policy decisions SHOULD be contained in the certificate used in the authentication of the exchange.

4.6.2.2 ID_IPV4_ADDR
The ID_IPV4_ADDR type specifies a single four (4) octet IPv4 address.

4.6.2.3 ID_FQDN
The ID_FQDN type specifies a fully-qualified domain name string. An example of a ID_FQDN is, "foo.bar.com". The string should not contain any terminators.

4.6.2.4 ID_USER_FQDN
The ID_USER_FQDN type specifies a fully-qualified username string, An example of a ID_USER_FQDN is, "piper@foo.bar.com". The string should not contain any terminators.

4.6.2.5 ID_IPV4_ADDR_SUBNET
The ID_IPV4_ADDR_SUBNET type specifies a range of IPv4 addresses, represented by two four (4) octet values. The first value is an IPv4 address. The second is an IPv4 network mask. Note that ones (1s) in the network mask indicate that the corresponding bit in the address is fixed, while zeros (0s) indicate a "wildcard" bit.

4.6.2.6 ID_IPV6_ADDR
The ID_IPV6_ADDR type specifies a single sixteen (16) octet IPv6address.

4.6.2.7 ID_IPV6_ADDR_SUBNET
The ID_IPV6_ADDR_SUBNET type specifies a range of IPv6 addresses, represented by two sixteen (16) octet values. The first value is an IPv6 address. The second is an IPv6 network mask. Note that ones (1s) in the network mask indicate that the corresponding bit in the address is fixed, while zeros (0s) indicate a "wildcard" bit.

4.6.2.8 ID_IPV4_ADDR_RANGE
The ID_IPV4_ADDR_RANGE type specifies a range of IPv4 addresses, represented by two four (4) octet values. The first value is the beginning IPv4 address (inclusive) and the second value is the ending IPv4 address (inclusive). All addresses falling between the two specified addresses are considered to be within the list.

4.6.2.9 ID_IPV6_ADDR_RANGE
The ID_IPV6_ADDR_RANGE type specifies a range of IPv6 addresses, represented by two sixteen (16) octet values. The first value is the beginning IPv6 address (inclusive) and the second value is the ending IPv6 address (inclusive). All addresses falling between the two specified addresses are considered to be within the list.

4.6.2.10 ID_DER_ASN1_DN
The ID_DER_ASN1_DN type specifies the binary DER encoding of an ASN.1 X.500 Distinguished Name [X.501] of the principal whose certificates are being exchanged to establish the SA.

4.6.2.11 ID_DER_ASN1_GN
The ID_DER_ASN1_GN type specifies the binary DER encoding of an ASN.1 X.500 GeneralName [X.509] of the principal whose certificates are being exchanged to establish the SA.

4.6.2.12 ID_KEY_ID
The ID_KEY_ID type specifies an opaque byte stream which may be used to pass vendor-specific information necessary to identify which pre-shared key should be used to authenticate Aggressive mode negotiations.

最后編輯于
?著作權(quán)歸作者所有,轉(zhuǎn)載或內(nèi)容合作請(qǐng)聯(lián)系作者
  • 序言:七十年代末幽邓,一起剝皮案震驚了整個(gè)濱河市尾序,隨后出現(xiàn)的幾起案子逆趣,更是在濱河造成了極大的恐慌,老刑警劉巖,帶你破解...
    沈念sama閱讀 212,599評(píng)論 6 492
  • 序言:濱河連續(xù)發(fā)生了三起死亡事件滴铅,死亡現(xiàn)場(chǎng)離奇詭異窘拯,居然都是意外死亡,警方通過查閱死者的電腦和手機(jī)躲株,發(fā)現(xiàn)死者居然都...
    沈念sama閱讀 90,629評(píng)論 3 385
  • 文/潘曉璐 我一進(jìn)店門片部,熙熙樓的掌柜王于貴愁眉苦臉地迎上來,“玉大人霜定,你說我怎么就攤上這事档悠。” “怎么了望浩?”我有些...
    開封第一講書人閱讀 158,084評(píng)論 0 348
  • 文/不壞的土叔 我叫張陵辖所,是天一觀的道長。 經(jīng)常有香客問我磨德,道長缘回,這世上最難降的妖魔是什么吆视? 我笑而不...
    開封第一講書人閱讀 56,708評(píng)論 1 284
  • 正文 為了忘掉前任,我火速辦了婚禮酥宴,結(jié)果婚禮上啦吧,老公的妹妹穿的比我還像新娘。我一直安慰自己拙寡,他們只是感情好授滓,可當(dāng)我...
    茶點(diǎn)故事閱讀 65,813評(píng)論 6 386
  • 文/花漫 我一把揭開白布。 她就那樣靜靜地躺著倒庵,像睡著了一般褒墨。 火紅的嫁衣襯著肌膚如雪。 梳的紋絲不亂的頭發(fā)上擎宝,一...
    開封第一講書人閱讀 50,021評(píng)論 1 291
  • 那天郁妈,我揣著相機(jī)與錄音,去河邊找鬼绍申。 笑死噩咪,一個(gè)胖子當(dāng)著我的面吹牛,可吹牛的內(nèi)容都是我干的极阅。 我是一名探鬼主播胃碾,決...
    沈念sama閱讀 39,120評(píng)論 3 410
  • 文/蒼蘭香墨 我猛地睜開眼,長吁一口氣:“原來是場(chǎng)噩夢(mèng)啊……” “哼筋搏!你這毒婦竟也來了仆百?” 一聲冷哼從身側(cè)響起,我...
    開封第一講書人閱讀 37,866評(píng)論 0 268
  • 序言:老撾萬榮一對(duì)情侶失蹤奔脐,失蹤者是張志新(化名)和其女友劉穎俄周,沒想到半個(gè)月后,有當(dāng)?shù)厝嗽跇淞掷锇l(fā)現(xiàn)了一具尸體髓迎,經(jīng)...
    沈念sama閱讀 44,308評(píng)論 1 303
  • 正文 獨(dú)居荒郊野嶺守林人離奇死亡峦朗,尸身上長有42處帶血的膿包…… 初始之章·張勛 以下內(nèi)容為張勛視角 年9月15日...
    茶點(diǎn)故事閱讀 36,633評(píng)論 2 327
  • 正文 我和宋清朗相戀三年,在試婚紗的時(shí)候發(fā)現(xiàn)自己被綠了排龄。 大學(xué)時(shí)的朋友給我發(fā)了我未婚夫和他白月光在一起吃飯的照片波势。...
    茶點(diǎn)故事閱讀 38,768評(píng)論 1 341
  • 序言:一個(gè)原本活蹦亂跳的男人離奇死亡,死狀恐怖橄维,靈堂內(nèi)的尸體忽然破棺而出尺铣,到底是詐尸還是另有隱情,我是刑警寧澤争舞,帶...
    沈念sama閱讀 34,461評(píng)論 4 333
  • 正文 年R本政府宣布凛忿,位于F島的核電站,受9級(jí)特大地震影響兑障,放射性物質(zhì)發(fā)生泄漏侄非。R本人自食惡果不足惜蕉汪,卻給世界環(huán)境...
    茶點(diǎn)故事閱讀 40,094評(píng)論 3 317
  • 文/蒙蒙 一、第九天 我趴在偏房一處隱蔽的房頂上張望逞怨。 院中可真熱鬧者疤,春花似錦、人聲如沸叠赦。這莊子的主人今日做“春日...
    開封第一講書人閱讀 30,850評(píng)論 0 21
  • 文/蒼蘭香墨 我抬頭看了看天上的太陽除秀。三九已至糯累,卻和暖如春,著一層夾襖步出監(jiān)牢的瞬間册踩,已是汗流浹背泳姐。 一陣腳步聲響...
    開封第一講書人閱讀 32,082評(píng)論 1 267
  • 我被黑心中介騙來泰國打工, 沒想到剛下飛機(jī)就差點(diǎn)兒被人妖公主榨干…… 1. 我叫王不留暂吉,地道東北人胖秒。 一個(gè)月前我還...
    沈念sama閱讀 46,571評(píng)論 2 362
  • 正文 我出身青樓,卻偏偏與公主長得像慕的,于是被迫代替她去往敵國和親阎肝。 傳聞我的和親對(duì)象是個(gè)殘疾皇子,可洞房花燭夜當(dāng)晚...
    茶點(diǎn)故事閱讀 43,666評(píng)論 2 350

推薦閱讀更多精彩內(nèi)容

  • NAME dnsmasq - A lightweight DHCP and caching DNS server....
    ximitc閱讀 2,822評(píng)論 0 0
  • 參考: https://developer.apple.com/library/content/documenta...
    anny_4243閱讀 5,945評(píng)論 0 8
  • 從學(xué)校回來的那天就收到了活動(dòng)贈(zèng)書《動(dòng)物知道生命的答案》嫉父,花了三天把它看完沛硅,我覺得這是繼蕾切爾?卡遜《寂靜的春天》之...
    庾郎閱讀 790評(píng)論 0 1
  • 現(xiàn)在我還是一名大二的學(xué)生稽鞭,在大學(xué)的生活也不知不覺過了兩年了鸟整,人們都說進(jìn)入大學(xué)你的一只腳已經(jīng)邁入了社會(huì)引镊,不得不說在大...
    VERAveraz閱讀 685評(píng)論 4 2
  • 在某一個(gè)瞬間,總想干一些事情篮条,并且很想很想弟头,就會(huì)有下定決心的樣子,斬荊截鐵的說一定堅(jiān)持涉茧,但我們總在不經(jīng)意間赴恨,一次又...
    走在成長路上閱讀 528評(píng)論 0 0