Page 199 - CISSO_Prep_ Guide
P. 199
the identity of the originating party. The SA contains the source
address and mode of IPsec to be used and a security parameter
index, which provides a unique identifier for the
communications session. A SA must be sent from each party to
the other since it authenticates the source.
When using AH, a new IPsec Authentication Header is inserted
into the packet after the IP header. The benefit of AH is that it
verifies the authenticity of the sender and the integrity of the
packet.
Also, when data confidentiality is required, IPsec can be used in
ESP mode. ESP provides the same benefits as AH and adds in
encryption of the data being transmitted.