EMAIL SUPPORT

dclessons@dclessons.com

LOCATION

NZ

Authentication between vBond & vEdge Router

Authentication between vBond & vEdge Router

Posted on Jan 27, 2020 (0)

Authentication between vBond & vEdge Router

When Ever a vEdge router is deployed in network, the first two things must be done

  • Establish the secure connection with vManage so that it can receive the full configuration
  • Establish the Secure connection with vSmart controller so that it can participate in Viptela Secure Overly network

The initial configuration of vEdge contains vBond system IP address or DNS name to establish the secure DTLS connection with it. This IP address is configured manually via initial configuration phase once vEdge is booted to start. Once the authentication between vBond and vEdge done successfully, vBond send the vManage and vSmart IP address to vEdge.

Once it is done, vEdge router tears down its connection with vBond and starts establishing DTLS connection with other two devices.

Below is the step by step procedure how automatic authentication occurs between vBond and vEdge.

vEdge router initiates DTLS connection to public IP address of the vBond, this encryption is provided by RSA and each device automatically generates RSA public and Private Key when it boots.

Once vBond receives the vEdge interface IP address and uses the outer IP address in the received packet to determine whether vEdge router is behind NAT and if it is true, vBond will create mapping of the vEdge Router public IP address and port with its Private IP address.

On this encrypted DTLS channel vBond and vEdge will start authentication process to each other.

Below procedure describes how vEdge router authenticates the vBond

  1. vBond will send the trusted root CA signed certificate to vEdge Router
  2. vEdge Router uses it chain of trust to extract the organization name from certificate and match it with its own, if they don’t match it will tear down the DTLS connection.
  3. If the name matches , vEdge router uses its root CA chain to verify that vBond certificate is signed by root CA , if it is not so then vEdge router will tear down the connection
  4. And if the Root certificate is validated vEdge router now knows that vBond is valid and after this process authentication of vBond orchestrator is complete

Now let’s see how vBond authenticates the vEdge Router.

  1. vBond send the 256 bit challenge to vEdge router and this challenge is a random value.
  2. The vEdge router sends following response for the challenge that include following:
  • vEdge Serial number
  • vEdge Chassis number
  • vEdge Board ID certificate
  • 256 bit random value signed by vEdge router Private key
  1. vBond after receiving this information , compares the serial and chassis number from its vEdge authorized device list file , if there is no match vBond will tear down the connection
  2. if the match is found vBond check if the signing of 256 bit random value is proper or not by using vEdge router public key which it extracts from Router Board ID certificate , if the Signing value is not matched vBond will down the DTLS connection
  3. if the value is proper , vBond uses root CA chain from vEdge router board ID certificate to validate that board id certificate is itself valid or not , the certificate is not valid the vBond will tear down the connection

If the Certificate is valid, vBond now knows that authentication is competed. Now when two way authentication is completed, vBond will perform the final steps of its orchestration process, by sending the message to the vEdge router and vSmart controller in parallel.

It send the following information to vEdge

  • IP address of vSmart controller in the network so that vEdge router can initiate connection to it.
  • Serial number of vSmart controller which are authorized to be in network

Now vBond send the following information to vSmart:

  • A message which announces the new vEdge router in domain
  • If the vEdge router is behind NAT gateway , vBond orchestrator send request to vSmart controller to initiate a session with vEdge router

Once it is done, vEdge router tears down DTLS connection with vBond orchestrator.


Comment

    You are will be the first.

LEAVE A COMMENT

Please login here to comment.