
Glossary
GL-10
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
IPSec
IP Security. A framework of open standards that provides data confidentiality, data integrity, and data
authentication between participating peers. IPSec provides these security services at the IP layer.
IPSec uses IKE to handle the negotiation of protocols and algorithms based on local policy and to
generate the encryption and authentication keys to be used by IPSec. IPSec can protect one or more
data flows between a pair of hosts, between a pair of security gateways, or between a security gateway
and a host.
IPSec Phase 1
The first phase of negotiating IPSec, includes the key exchange and the ISAKMP portions of IPSec.
IPSec Phase 2
The second phase of negotiating IPSec. Phase two determines the type of encryption rules used for
payload, the source and destination that will be used for encryption, the definition of interesting traffic
according to access lists, and the IPSec peer. IPSec is applied to the interface in Phase 2.
IPSec transform set
A transform set specifies the IPSec protocol, encryption algorithm, and hash algorithm to use on traffic
matching the IPSec policy. A transform describes a security protocol (AH or ESP) with its
corresponding algorithms. The IPSec protocol used in almost all transform sets is ESP with the DES
algorithm and HMAC-SHA for authentication.
ISAKMP
Internet Security Association and Key Management Protocol. A protocol framework that defines
payload formats, the mechanics of implementing a key exchange protocol, and the negotiation of a
security association. See IKE.
ISP
Internet Service Provider. An organization that provides connection to the Internet via their services,
such as modem dial in over telephone voice lines or DSL.
J
JTAPI
Java Telephony Application Programming Interface. A Java-based API supporting telephony
functions. See also TAPI.
K
key
A data object used for encryption, decryption, or authentication.
L
LAN
Local area network. A network residing in one location, such as a single building or campus. See also
Internet, intranet, and network.
layer, layers
Networking models implement layers with which different protocols are associated. The most
common networking model is the OSI model, which consists of the following 7 layers, in order:
physical, data link, network, transport, session, presentation, and application.
LCN
Logical channel number.
LDAP
Lightweight Directory Access Protocol. LDAP provides management and browser applications with
access to X.500 directories.
Comentarios a estos manuales