IPsec and IKE Administration Guide
    
Numbers and Symbols
 
 > prompt
  ikeadm command mode ( Index Term Link )
  ipseckey command mode ( Index Term Link )
 
 3DES encryption algorithm
  and IPsec ( Index Term Link )
  key length ( Index Term Link )
    
A
 
 -a option
  ikecert certdb command ( Index Term Link )
  ikecert certrldb command ( Index Term Link )
 
 -A option, ikecert command ( Index Term Link )
 
 -a option
  ikecert command ( Index Term Link )
  ipsecconf command ( Index Term Link ) ( Index Term Link )
 
 accelerating
  IKE computations ( Index Term Link ) ( Index Term Link )
 
 AES encryption algorithm, and IPsec ( Index Term Link )
 
 AH
  See authentication header (AH)
 
 auth_algs security option, ifconfig command ( Index Term Link )
 
 authentication algorithms
  IKE ( Index Term Link )
  IPsec
   MD5 ( Index Term Link )
   SHA ( Index Term Link )
  specifying for IPsec ( Index Term Link )
 
 authentication header (AH)
  IPsec protection mechanism ( Index Term Link )
  module in IPsec ( Index Term Link )
  protecting IP datagram ( Index Term Link )
  protecting IP packets ( Index Term Link )
    
B
 
 Blowfish encryption algorithm, and IPsec ( Index Term Link )
 
 bypassing
  IPsec on LAN ( Index Term Link )
  IPsec policy ( Index Term Link )
    
C
 
 -c option, in.iked daemon ( Index Term Link )
 
 cert_root keyword ( Index Term Link )
 
 cert_trust keyword ( Index Term Link )
 
 certificate revocation lists
  See CRLs
 
 certificates
  adding to database ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  from CA ( Index Term Link )
  from CA on hardware ( Index Term Link )
  hardware storage ( Index Term Link )
  ignoring CRLs ( Index Term Link )
  in ike/config file ( Index Term Link )
  listing ( Index Term Link )
  request ( Index Term Link ) ( Index Term Link )
  request on hardware ( Index Term Link )
  self-signed ( Index Term Link )
  self-signed on hardware ( Index Term Link )
  signed by CA ( Index Term Link )
  storing on hardware ( Index Term Link ) ( Index Term Link )
 
 commands
  IKE
   ikeadm command ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   ikecert command ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   in.iked daemon ( Index Term Link )
  IPsec
   ipsecconf command ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   ipseckey command ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   list ( Index Term Link )
   security considerations ( Index Term Link )
   snoop command ( Index Term Link ) ( Index Term Link )
 
 computations
  accelerating IKE in hardware ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 configuring
  IKE ( Index Term Link )
  ike/config file ( Index Term Link )
  IPsec ( Index Term Link )
  ipsecinit.conf file ( Index Term Link )
 
 CRLs
  accessing from central location ( Index Term Link )
  crls database ( Index Term Link )
  ignoring ( Index Term Link )
  ikecert certrldb command ( Index Term Link )
  listing ( Index Term Link )
    
D
 
 -D option, ikecert command ( Index Term Link )
 
 daemons
  in.iked daemon ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 datagrams, IP ( Index Term Link )
 
 DES encryption algorithm, and IPsec ( Index Term Link )
 
 /dev/ipsecah file ( Index Term Link )
 
 /dev/ipsecesp file ( Index Term Link )
 
 /dev/random device ( Index Term Link )
 
 digital signatures
  DSA ( Index Term Link )
  RSA ( Index Term Link ) ( Index Term Link )
 
 directory name (DN), for accessing CRLs ( Index Term Link )
 
 DSS authentication algorithm ( Index Term Link )
    
E
 
 encapsulating security payload (ESP)
  description ( Index Term Link )
  IPsec protection mechanism ( Index Term Link )
  protecting IP packets ( Index Term Link )
  tuning with ndd command ( Index Term Link )
 
 encr_algs security option, ifconfig command ( Index Term Link )
 
 encr_auth_algs security option, ifconfig command ( Index Term Link )
 
 encryption algorithms
  IPsec ( Index Term Link )
   3DES ( Index Term Link )
   AES ( Index Term Link )
   Blowfish ( Index Term Link )
   DES ( Index Term Link )
  specifying for IPsec ( Index Term Link )
 
 ESP
  See encapsulating security payload (ESP)
 
 /etc/inet/ike/config file
  and CRLs ( Index Term Link )
  and ikecert command ( Index Term Link )
  cert_root keyword ( Index Term Link )
  cert_trust keyword ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  ignore_crls keyword ( Index Term Link )
  ldap-list keyword ( Index Term Link )
  PKCS #11 library entry ( Index Term Link )
  pkcs11_path keyword ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  proxy keyword ( Index Term Link )
  public key certificates ( Index Term Link )
  putting certificates on hardware ( Index Term Link )
  rsa_encrypt authentication method ( Index Term Link )
  sample ( Index Term Link )
  security considerations ( Index Term Link )
  self-signed certificates ( Index Term Link )
  summary ( Index Term Link )
  use_http keyword ( Index Term Link )
  with preshared keys ( Index Term Link )
 
 /etc/inet/ike/crls directory ( Index Term Link )
 
 /etc/inet/ike/publickeys directory ( Index Term Link )
 
 /etc/inet/hosts file ( Index Term Link )
 
 /etc/inet/ipnodes file ( Index Term Link )
 
 /etc/inet/ipsecinit.conf file ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 /etc/inet/ipsecpolicy.conf file ( Index Term Link )
 
 /etc/inet/secret/ike.privatekeys directory ( Index Term Link )
 
 /etc/init.d/inetinit script ( Index Term Link )
    
F
 
 -f option, ipseckey command ( Index Term Link )
 
 files
  IKE
   crls directory ( Index Term Link ) ( Index Term Link )
   ike/config file ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   ike.preshared file ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   ike.privatekeys directory ( Index Term Link )
   ike.privatekeys file ( Index Term Link )
   publickeys directory ( Index Term Link ) ( Index Term Link )
  IPsec
   /etc/inet/ipsecpolicy.conf file ( Index Term Link )
   /etc/init.d/inetinit file ( Index Term Link )
   ipsecinit.conf file ( Index Term Link ) ( Index Term Link )
   ipseckeys file ( Index Term Link )
  ipsecinit.conf file ( Index Term Link )
    
H
 
 hardware
  accelerating IKE computations ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  storing IKE keys ( Index Term Link ) ( Index Term Link )
 
 HMAC-MD5 authentication algorithm, and IPsec ( Index Term Link )
 
 HMAC-SHA authentication algorithm, and IPsec ( Index Term Link )
 
 hosts file ( Index Term Link )
    
I
 
 ifconfig command
  auth_algs security option ( Index Term Link )
  encr_algs security option ( Index Term Link )
  encr_auth_algs security option ( Index Term Link )
  IPsec security options ( Index Term Link )
  setting tunnels ( Index Term Link )
 
 ignore_crls keyword ( Index Term Link )
 
 IKE
  changing privilege level ( Index Term Link )
  checking if valid policy ( Index Term Link )
  checking privilege level ( Index Term Link )
  configuring ( Index Term Link ) ( Index Term Link )
  crls database ( Index Term Link )
  /etc/inet/ike/config file ( Index Term Link ) ( Index Term Link )
  handling CRLs ( Index Term Link )
  hardware acceleration ( Index Term Link )
  hardware storage of keys ( Index Term Link )
  ike.preshared file ( Index Term Link )
  ike.privatekeys database ( Index Term Link )
  ikeadm command ( Index Term Link ) ( Index Term Link )
  ikecert certdb command ( Index Term Link )
  ikecert certlocal command ( Index Term Link )
  ikecert certrldb command ( Index Term Link )
  ikecert command ( Index Term Link )
  ikecert tokens command ( Index Term Link )
  implementing ( Index Term Link ) ( Index Term Link )
  in.iked daemon ( Index Term Link )
  Internet Key Exchange ( Index Term Link )
  ISAKMP SAs ( Index Term Link )
  overview ( Index Term Link )
  perfect forward secrecy ( Index Term Link )
  Phase 1 exchange ( Index Term Link )
  Phase 2 exchange ( Index Term Link )
  PKCS #11 library ( Index Term Link ) ( Index Term Link )
  publickeys database ( Index Term Link )
  refreshing preshared keys ( Index Term Link ) ( Index Term Link )
  RSA encryption algorithm ( Index Term Link )
  security associations ( Index Term Link ) ( Index Term Link )
  with certificates ( Index Term Link )
  with hardware ( Index Term Link )
  with preshared keys ( Index Term Link )
 
 ike/config file
  See /etc/inet/ike/config file
 
 ike_mode keyword ( Index Term Link )
 
 ike.preshared file ( Index Term Link ) ( Index Term Link )
  sample ( Index Term Link )
 
 ike.privatekeys database ( Index Term Link )
 
 ikeadm command
  changing privilege level ( Index Term Link )
  checking privilege level ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  interactive mode ( Index Term Link )
 
 ikecert certdb command ( Index Term Link )
 
 ikecert certlocal command ( Index Term Link )
 
 ikecert certrldb command ( Index Term Link )
 
 ikecert command
  description ( Index Term Link ) ( Index Term Link )
 
 ikecert tokens command ( Index Term Link )
 
 in.iked daemon
  activating ( Index Term Link )
  changing privilege level ( Index Term Link )
  checking privilege level ( Index Term Link )
  description ( Index Term Link )
  stop and start ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 inetd.conf file, IPsec ( Index Term Link )
 
 inetinit script ( Index Term Link )
 
 interactive mode
  ikeadm command ( Index Term Link )
  ipseckey command ( Index Term Link )
 
 IP datagrams, protecting with IPsec ( Index Term Link )
 
 IP forwarding
  in VPNs ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 IP security architecture
  See IPsec
 
 ipnodes file ( Index Term Link )
 
 IPsec
  activating ( Index Term Link )
  adding security associations ( Index Term Link )
  authentication algorithms ( Index Term Link )
  authentication headers ( Index Term Link )
  bypassing ( Index Term Link ) ( Index Term Link )
  configuring ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  creating security associations ( Index Term Link )
  /dev/ipsecah file ( Index Term Link )
  /dev/ipsecesp file ( Index Term Link )
  encapsulating data ( Index Term Link )
  encapsulating security payload ( Index Term Link ) ( Index Term Link )
  encryption algorithms ( Index Term Link ) ( Index Term Link )
  enforcement mechanisms ( Index Term Link )
  /etc/hosts file ( Index Term Link )
  /etc/inet/ipnodes file ( Index Term Link )
  /etc/inet/ipsecinit.conf file ( Index Term Link ) ( Index Term Link )
  /etc/inet/ipsecpolicy.conf file ( Index Term Link )
  /etc/init.d/inetinit script ( Index Term Link )
  extensions to utilities
   ifconfig command ( Index Term Link )
   snoop command ( Index Term Link )
  ifconfig command ( Index Term Link )
   configuring VPN ( Index Term Link )
   security options ( Index Term Link )
   setting policy ( Index Term Link )
  implementing ( Index Term Link )
  in.iked daemon ( Index Term Link )
  inbound packet process ( Index Term Link )
  inetd.conf file ( Index Term Link )
  ipsecconf command ( Index Term Link ) ( Index Term Link )
  ipsecinit.conf file ( Index Term Link )
  ipseckey command ( Index Term Link ) ( Index Term Link )
  key management ( Index Term Link )
  keying utilities
   IKE ( Index Term Link )
   ipseckey command ( Index Term Link )
  ndd command ( Index Term Link )
  outbound packet process ( Index Term Link )
  overview ( Index Term Link )
  policy command ( Index Term Link )
  policy files ( Index Term Link )
  protecting packets ( Index Term Link )
  protection mechanisms ( Index Term Link )
  protection policy ( Index Term Link )
  replacing security associations ( Index Term Link )
  route command ( Index Term Link )
  securing a web server ( Index Term Link )
  securing traffic ( Index Term Link )
  security associations ( Index Term Link )
  security associations database ( Index Term Link )
  security parameter index (SPI) ( Index Term Link )
  security protocols ( Index Term Link )
  setting policy permanently ( Index Term Link )
  setting policy temporarily ( Index Term Link )
  snoop command ( Index Term Link )
  specifying authentication algorithms ( Index Term Link )
  specifying encryption algorithms ( Index Term Link )
  transport mode ( Index Term Link )
  tunnel mode ( Index Term Link )
  tunnels ( Index Term Link )
  virtual private networks (VPN) ( Index Term Link )
 
 ipsecconf command
  -a option ( Index Term Link ) ( Index Term Link )
  activating IPsec ( Index Term Link )
  configuring IPsec policy ( Index Term Link ) ( Index Term Link )
  security considerations ( Index Term Link )
 
 ipsecconf command, security considerations ( Index Term Link )
 
 ipsecinit.conf file
  sample ( Index Term Link )
  security considerations ( Index Term Link )
 
 ipseckey command ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  managing IPsec keys ( Index Term Link )
  security considerations ( Index Term Link )
 
 ipseckeys file, storing IPsec keys ( Index Term Link )
 
 ipsecpolicy.conf file ( Index Term Link )
 
 ISAKMP SAs ( Index Term Link )
    
K
 
 -kc option
  ikecert certlocal command ( Index Term Link ) ( Index Term Link )
 
 key management
  automatic ( Index Term Link ) ( Index Term Link )
  IKE ( Index Term Link )
  IPsec ( Index Term Link )
  manual ( Index Term Link )
 
 keying utilities
  IKE protocol ( Index Term Link )
  ipseckey command ( Index Term Link )
 
 keys
  automatic management ( Index Term Link )
  generating random numbers for ( Index Term Link )
  ike.privatekeys database ( Index Term Link )
  ike/publickeys database ( Index Term Link )
  managing IPsec ( Index Term Link )
  manual management ( Index Term Link )
  preshared ( Index Term Link )
  storing on hardware ( Index Term Link )
 
 keystore name
  See token ID
 
 -ks option, ikecert certlocal command ( Index Term Link )
    
L
 
 ldap-list keyword, ike/config file ( Index Term Link )
 
 libraries
  PKCS #11 ( Index Term Link ) ( Index Term Link )
 
 local file name services
  /etc/inet/hosts file ( Index Term Link )
  /etc/inet/ipnodes file ( Index Term Link )
    
M
 
 machines, protecting communication ( Index Term Link )
 
 MD5 authentication algorithm
  and IPsec ( Index Term Link )
  key length ( Index Term Link )
    
N
 
 ndd command
  configuring VPN ( Index Term Link )
  IP forwarding ( Index Term Link )
  tuning IPsec ( Index Term Link )
    
O
 
 od command ( Index Term Link ) ( Index Term Link )
 
 /opt/SUNWconn/lib/libpkcs11.so entry, in ike/config file ( Index Term Link )
    
P
 
 -p option, in.iked daemon ( Index Term Link )
 
 packets
  protecting with IKE ( Index Term Link )
  protecting with IPsec ( Index Term Link )
   inbound ( Index Term Link )
   outbound ( Index Term Link )
  verifying IPsec protection ( Index Term Link )
 
 perfect forward secrecy, IKE ( Index Term Link )
 
 PF_KEY socket interface
  IPsec ( Index Term Link ) ( Index Term Link )
 
 PKCS #11 library ( Index Term Link ) ( Index Term Link )
  in ike/config file ( Index Term Link )
 
 pkcs11_path keyword ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 policy files
  ike/config file ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  ipsecinit.conf file ( Index Term Link )
  ipsecpolicy.conf temporary file ( Index Term Link )
  security considerations ( Index Term Link )
 
 preshared keys, task map ( Index Term Link )
 
 privilege level
  checking in IKE ( Index Term Link )
  setting in IKE ( Index Term Link )
 
 protecting
  packets between two intranets ( Index Term Link )
  packets between two systems ( Index Term Link )
  web server with IPsec ( Index Term Link )
 
 protection mechanisms, IPsec ( Index Term Link )
 
 proxy keyword, ike/config file ( Index Term Link )
 
 public key certificates
  See certificates
 
 publickeys database ( Index Term Link )
    
R
 
 random numbers
  /dev/random device ( Index Term Link )
  generating with od command ( Index Term Link ) ( Index Term Link )
 
 route command, IPsec ( Index Term Link )
 
 rsa_encrypt authentication method, ike/config file ( Index Term Link )
 
 RSA encryption algorithm ( Index Term Link ) ( Index Term Link )
    
S
 
 security
  IKE ( Index Term Link )
  IPsec ( Index Term Link )
 
 security associations (SAs)
  adding IPsec ( Index Term Link )
  creating IPsec SAs ( Index Term Link )
  flushing IPsec SAs ( Index Term Link )
  IKE ( Index Term Link )
  IPsec ( Index Term Link ) ( Index Term Link )
  IPsec database ( Index Term Link )
  ISAKMP ( Index Term Link )
  random number generation ( Index Term Link )
  replacing IPsec SAs ( Index Term Link )
  replacing ISAKMP SAs ( Index Term Link )
 
 security associations database (SADB) ( Index Term Link )
 
 security considerations
  authentication header ( Index Term Link )
  configuring IKE ( Index Term Link )
  configuring IPsec ( Index Term Link )
  encapsulating security payload ( Index Term Link )
  ike/config file ( Index Term Link )
  ipsecconf command ( Index Term Link )
  ipsecinit.conf file ( Index Term Link )
  ipseckey command ( Index Term Link )
  ipseckeys file ( Index Term Link )
  key length ( Index Term Link )
  latched sockets ( Index Term Link )
  preshared keys ( Index Term Link )
 
 security parameter index (SPI)
  description ( Index Term Link )
  key size ( Index Term Link )
 
 SHA authentication algorithm, and IPsec ( Index Term Link )
 
 slots, in hardware ( Index Term Link )
 
 snoop command
  viewing protected packets ( Index Term Link ) ( Index Term Link )
 
 sockets
  IPsec security ( Index Term Link )
  security considerations ( Index Term Link )
 
 storing
  IKE keys on disk ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  IKE keys on hardware ( Index Term Link ) ( Index Term Link )
 
 Sun Crypto Accelerator 1000 board ( Index Term Link ) ( Index Term Link )
 
 Sun Crypto Accelerator 4000 board ( Index Term Link )
  accelerating IKE computations ( Index Term Link )
  storing IKE keys ( Index Term Link )
 
 systems, protecting communication ( Index Term Link )
    
T
 
 -T option
  ikecert command ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 -t option, ikecert command ( Index Term Link )
 
 task maps
  accelerating IKE keys on hardware ( Index Term Link )
  IKE ( Index Term Link )
  IKE with hardware ( Index Term Link )
  IKE with preshared keys ( Index Term Link )
  IKE with public key certificates ( Index Term Link )
  IPsec ( Index Term Link )
  storing IKE keys on hardware ( Index Term Link )
 
 token ID, in hardware ( Index Term Link )
 
 tokens argument, ikecert command ( Index Term Link )
 
 transport mode, IPsec ( Index Term Link )
 
 Triple-DES encryption algorithm, and IPsec ( Index Term Link )
 
 tunnel mode, IPsec ( Index Term Link )
 
 tunnels
  ifconfig security options ( Index Term Link )
  IPsec ( Index Term Link )
  protecting packets ( Index Term Link )
    
U
 
 uniform resource indicator (URI), for accessing CRLs ( Index Term Link )
 
 use_http keyword, ike/config file ( Index Term Link )
    
V
 
 -V option, snoop command ( Index Term Link )
 
 virtual private networks (VPN)
  configuring with ndd command ( Index Term Link ) ( Index Term Link )
  constructed with IPsec ( Index Term Link )
  example ( Index Term Link )
  setting up ( Index Term Link )
    
W
 
 web servers, securing with IPsec ( Index Term Link )