-
Anti-replay
-
Non-repudiation
-
Encryption
-
Authentication
EXPLANATION
Internet Protocol Security (IPSec)
Cisco IOS uses the industry-standard IPSec protocol suite to enable advanced
VPN features. The PIX IPSec implementation is based on the Cisco IOS IPSec that
runs in Cisco routers.
IPSec acts at the network layer, protecting and authenticating IP packets
between a PIX Firewall and other participating IPSec devices (peers), such as
other PIX Firewalls, Cisco routers, the Cisco Secure VPN Client, the VPN 3000
Concentrator series, and other IPSec-compliant products.
IPSec enables the following Cisco IOS VPN features:
- Data confidentiality—The IPSec sender can encrypt packets
before transmitting them across a network.
- Data integrity—The IPSec receiver can authenticate packets
sent by the IPSec sender to ensure that the data has not been altered during
transmission.
- Data origin authentication—The IPSec receiver can
authenticate the source of the IPSec packets sent. This service is dependent
upon the data integrity service.
- Antireplay—The IPSec receiver can detect and reject replayed
packets.