User guide
Rev 2.2 Jun.11 24
B
B: IPsec Architecture
Standards of the M2M IPSec Support
SierraWirelessM2MIPSecsupportsthefollowi ngstandards:
• RFC1829–“TheESPDES‐CBCTransform”
• RFC2401–“SecurityArchitecturefortheInternet
Protocol”
• RFC2403–“TheUseofHMAC‐MD5‐96withinESPand
AH”
• RFC2404–“TheUseofHMAC‐SHA‐1‐96withinESPand
AH”
• RFC2405–“TheESPDES‐CBCCipherAlgorithmWith
ExplicitIV”
• RFC2406–“IPEncapsulatingSecurityPayload(ESP)”
• RFC2410–“TheNULLEncryptionAlgorithmandItsUse
WithIPSec”
• RFC2451–“TheESPCBC‐ModeCipherAlgorithms”
• RFC3602–“TheAES‐CBCCipherAlgorithmandItsUse
withIPSec”(futureenhancement)
Security Algorithms:
1. InternetKeyExchange(IKE)
a. AuthenticationforIKEMessages(Hashing
Algorithms)
· MD5
· SHA1
b. ExchangeModesSupportedinPhase1andPhase2of
IKE
· MainMode
· AggressiveMode
· QuickMode
· InformationalMode
c. AuthenticationMethods(usedinPhase1)
· Authenticationusingpre‐sharedkeys
· AuthenticationusingRSAsignatures
d. OakleyGroups:usedduringPhase1tocalculatekeys
fortheIKESecurityAssociation
· FirstOakleyGroup(MODP768)
· SecondOakleyGroup(MODP1024)
· FifthOakleyGroup(MODP1536)
· MODP2048(available,butnotcurrentlysupported)
· MODP3072(available,butnotcurrentlysupported)