I_RFC2409_4_11.seq [-tooloption ...] -pkt I_RFC2409_4_11.def -tooloption : v6eval tool option See also ike_common.def and ike_ipsec.def and ike_addr.def and ike_pkt_ph1_recv.def and ike_pkt_ph2_recv.def=end html =head1 INITIALIZATION =begin html
HOST-2(TN):responder
|3ffe:501:ffff:101::11
|
Net-y --+--------+------------------------ 3ffe:501:ffff:101::/64
|
|
ROUTER-1(TN)
|3ffe:501:ffff:100::11
|
Net-z --+--------+------------------------ 3ffe:501:ffff:100::/64
|
|3ffe:501:ffff:100:XXXX
NUT:initiator
XXXX: EUI64 address
| Parameter | Value | |
| ISAKMP | SA Attributes | - 3DES in CBC mode - SHA - RSA signatures. - MODP over group number two. |
| Machine | Src | Dest | Phase I | Phase II | ||||||||||||
| Ex mode | Key Value | Enc Alg | Hash Alg | Auth Method | DH Group | PH1 Lt | IDx | Proto ID | Trans ID | Mode | Auth Alg | PH2 Lt | Upper | |||
| NUT | NUT addr | HOST-2 addr | Main | 3DES* | SHA* | RSA signatures | 2* | 8 Hour | NUT addr | PROTO_IPSEC_ESP | ESP_3DES | Transport | HMAC-SHA | 8 Hour | any | |
| HOST-2 | HOST-2 addr | NUT addr | Main | 3DES | SHA | RSA signatures | 2 | 8 Hour | HOST-2 addr | PROTO_IPSEC_ESP | ESP_3DES | Transport | HMAC-SHA | 8 Hour | any | |
In order to start the negotiation of IKE,
NUT transmits Echo Request to TN(HOST-2).
=end html
=head1 TEST PROCEDURE
=begin html
This test check is following.=end html =head1 JUDGEMENT The first message Attributes(RSA sign:3) must be included. And must conform to above Configuration. =head1 TERMINATION Clean up SAD and SPD =head1 REFERENCE =begin html
IDENTITY PROTECTION EXCHANGE
# Initiator(NUT) Direction Responder(TN) (1) HDR; SA ========> Judgement (Check *1)
1. Receive the first message from NUT In the first message (1), the initiator generates a proposal it considers adequate to protect traffic for the given situation. The Security Association, Proposal, and Transform payloads are included in the Security Association payload (for notation purposes).
RFC2409 4.Introduction=end html =head1 SEE ALSO perldoc V6evalTool =begin html
(omit)
IKE implementations MUST support the following attribute values:
- DES [DES] in CBC mode with a weak, and semi-weak, key check (weak and semi-weak keys are referenced in [Sch96] and listed in Appendix A). The key is derived according to Appendix B.
- MD5 [MD5] and SHA [SHA].
- Authentication via pre-shared keys.
- MODP over default group number one (see below).
In addition, IKE implementations SHOULD support: 3DES for encryption; Tiger ([TIGER]) for hash; the Digital Signature Standard, RSA [RSA] signatures and authentication with RSA public key encryption; and MODP group number 2. IKE implementations MAY support any additional encryption algorithms defined in Appendix A and MAY support ECP and EC2N groups.
(omit)
IKE.html IKE Test Common Utility=end html =cut