System Administration Guide, Volume 3

Introduction to IPsec

IPsec provides security associations that include secure datagram authentication and encryption mechanisms within IP. When you invoke IPsec, it applies the security mechanisms to IP datagrams that you have enabled in the IPsec global policy file.

The following figure shows how an IP addressed packet, as part of an IP datagram, proceeds when IPsec has been invoked on an outbound packet. As you can see from the flow diagram, authentication header (AH) and encapsulated security payload (ESP) entities can be applied to the packet. Subsequent sections describe how you apply these entities, as well as athentication and encryption algorithms.

Figure 18-1 IPsec Applied to Outbound Packet Process

Graphic

The following figure shows the IPsec inbound process.

Figure 18-2 IPsec Applied to Inbound Packet Process

Graphic