Test IKEv2.EN.I.1.1.6.3: Sending Multiple Transforms for IKE_SA
Part A: Multiple Encryption Algorithms (ADVANCED)
To verify an IKEv2 device properly transmits IKE_SA_INIT request with multiple
transforms for IKE_SA.
* [RFC 4306] - Sections 2.7 and 3.3
* Network Topology
Connect the devices according to the Common Topology.
* Configuration
In each part, configure the devices according to the following configuration:
|
IKE_SA_INIT exchanges Algorithms |
| Encryption |
PRF |
Integrity |
D-H Group |
| Part A |
ENCR_3DES ENCR_AES_CBC |
PRF_HMAC_SHA1 |
AUTH_HMAC_SHA1_96 |
Group2 |
* Pre-Sequence and Cleanup Sequence
IKEv2 on the NUT is disabled after each part.
NUT TN1
(End-Node) (End-Node)
| |
|------------------->| IKE_SA_INIT request (HDR, SAi1, KEi, Ni)
| | (Judgement #1)
| |
V V
Part A: Multiple Encryption Algorithms (ADVANCED)
1. NUT starts to negotiate with TN1 by sending IKE_SA_INIT request including a SA payload
as described above.
2. Observe the messages transmitted on Link A.
Part A
Step 2: Judgment #1
The NUT transmits an IKE_SA_INIT response including "ENCR_3DES",
"ENCR_AES_CBC", "PRF_HMAC_SHA1", "AUTH_HMAC_SHA1_96" and "D-H group
2" as accepted algorithms.
* None.