Internet Protocol Security (IPSec) can be configured to prevent data theft and spoofing during data transmission in a network.
A security association (SA) must be established so that IPSec can protect transmitted data. An SA is a unidirectional logical connection set up for security purpose and specifies the elements used by two IPSec peers (two parties that use the IPSec protocol to protect data transmitted between them). The elements of an SA include the following:
The first three elements are specified in an IPSec proposal. To configure IPSec functions, first configure an IPSec proposal on the IPSec peers, and then configure an SA.