Posts

Showing posts with the label Security

This year and a New Year's resolution

Image
The last time I wrote something in my blog was a year ago! This is not what conscious people should do. Apart of my laziness, there was a reason for that – it was a tough time.  First, Veon to whom I devoted 7 years and me are no longer together. Veon decided to outsource all its technology staff, broke all organization structures, and laid off all IT management (three "alls" in a row, eh 😁). I reached my ceiling as an engineer and during last several months mostly worked as a field manager trying to plug holes. Me and Bi.Zone In spring, I went to Moscow and have been working as network security specialist at Bi.Zone for the half a year. It was an amazing time. Good office, young and brilliant colleagues, trips to Kazakhstan. What is more, I passed this little one, which took me 3 month of learning and practicing.  Bi.Zone I miss you and I appreciate that intensive experience in data centers, Juniper, Palo Alto, virtualization, automation,...

С чем кушатьIPSec

Image
Как вдруг выяснилось IPsec это набор протоколов, типа стека TCP\IP Сказать у нас IPSec - не сказать толком ничего, нужно указать подробности. Распутаем термины: ISAKMP - стандарт, описывает установку соединения, согласование его параметров. IKE - протокол, который реализует концепт ISAKMP. Результатом работы является пара SA с каждой стороны - этот типа метки туннеля в MPLS. По существу SA - набор параметров соединения: алгоритм хеша, шифрования, адрес пира, способ аутентификации пира (предустановленные ключи, открытые ключи, например RSA) , нумерация пакетов. А чего согласовываем? Первым делом - как участники аутентифицируют трафик друг друга - по протоколам  AH  (протоколы  ESP тоже могут выполнять функцию AH). Задача - идентифицировать вторую сторону. Для аутентификации и шифра нужны ключи. Для первого можно использовать заранее настроенный пароль (pre-share) или ключи  RSA, которые могут быть подтверждены сертифик...