|
Explanation: FWZ support in-place encryption, encrypting the payload portion (data) of the packet and leaving the original TCP/IP headers intact. Because packet size is not increased, in-place encryption allows for better network performance than the provided by IKE encryption. FWZ encryption gets certified Diffie-Hellman public keys from a trusted certificate authority, the CP Management server. See Page 7.16 of CCSE NG Official Courseware. (VPN1-FW1 Management II NG FP-1). Note: FWZ is and has not been supported by checkpoint since NGFP1.
|