Test IKEv2.EN.I.1.1.6.3: Sending Multiple Transforms for IKE_SA
Part D: Multiple D-H Groups (ADVANCED)
To verify an IKEv2 device properly transmits IKE_SA_INIT request with multiple
transforms for IKE_SA.
* [RFC 4306] - Sections 2.7 and 3.3
* Network Topology
Connect the devices according to the Common Topology.
* Configuration
In each part, configure the devices according to the following configuration:
|
IKE_SA_INIT exchanges Algorithms |
| Encryption |
PRF |
Integrity |
D-H Group |
| Part D |
ENCR_3DES |
PRF_HMAC_SHA1 |
AUTH_HMAC_SHA1_96 |
Group2 Group14 |
* Pre-Sequence and Cleanup Sequence
IKEv2 on the NUT is disabled after each part.
NUT TN1
(End-Node) (End-Node)
| |
|------------------->| IKE_SA_INIT request (HDR, SAi1, KEi, Ni)
| | (Judgement #1)
| |
V V
Part D: Multiple D-H Groups (ADVANCED)
7. TN1 starts to negotiate with NUT by sending IKE_SA_INIT request including a SA payload
as described above.
8. Observe the messages transmitted on Link A.
Part D
Step 8: Judgment #1
The NUT transmits an IKE_SA_INIT response including "ENCR_3DES",
"PRF_HMAC_SHA1", "AUTH_HMAC_SHA1_96", "D-H group 2" and "D-H group 14" as
accepted algorithms.
* None.