V6100 and V7122 User Guide
327
IKE Specifications:
Authentication mode - pre-shared key only.
Main mode is supported for IKE Phase 1.
Supported IKE SA encryption algorithms - DES and 3DES.
Hash types for IKE SA - SHA1 and MD5.
IPSec
IPSec is responsible for encrypting and decrypting the IP streams.
The IPSec Security Policy Database (SPD) table defines up to 20 IP peers to which the
IPSec security is applied. IPSec can be applied to all packets designated to a specific IP
address or to a specific IP address, port (source or destination) and protocol type.
Each outgoing packet is analyzed and compared to the SPD table. The packet's destination
IP address (and optionally, destination port, source port and protocol type) are compared to
each entry in the table. If a match is found, the gateway checks if an SA already exists for
this entry. If it doesn’t, the IKE protocol is invoked (see
IKE
) and an IPSec SA is established.
The packet is encrypted and transmitted. If a match isn’t found, the packet is transmitted un-
encrypted.
An incoming packet whose parameters match one of the entries of the SPD table
but is received un-encrypted, is dropped.
IPSec Specifications:
Transport mode only.
Encapsulation Security Payload (ESP) only.
Support for Cipher Block Chaining (CBC).
Supported IPSec SA encryption algorithms - DES and 3DES.
Hash types for IPSec SA are SHA1 and MD5.
Configuring the IPSec and IKE
To enable IPSec and IKE on the gateway set the
ini
file parameter ‘EnableIPSec’ to 1. Note
that when this parameter is defined, even if no table entries exist, the V7122 channel
capacity is reduced by 4 DSP cores (for example, 24 channels in the default template). On
the TP-260 and V6100 the channel capacity isn’t reduced.
Summary of Contents for TP-1610
Page 28: ...28 V6100 and V7122 User Guide Reader s Notes ...
Page 48: ...48 V6100 and V7122 User Guide Reader s Notes ...
Page 72: ...72 V6100 and V7122 User Guide Reader s Notes ...
Page 80: ...80 V6100 and V7122 User Guide Reader s Notes ...
Page 152: ...152 V6100 and V7122 User Guide Reader s Notes ...
Page 262: ...262 V6100 and V7122 User Guide Reader s Notes ...
Page 284: ...284 V6100 and V7122 User Guide Reader s Notes ...
Page 291: ...V6100 and V7122 User Guide 291 Figure 95 V7122 Startup Process ...
Page 324: ...324 V6100 and V7122 User Guide Reader s Notes ...
Page 354: ...354 V6100 and V7122 User Guide Reader s Notes ...
Page 374: ...374 V6100 and V7122 User Guide Reader s Notes ...
Page 382: ...382 V6100 and V7122 User Guide Figure 130 Example of a User Information File Reader s Notes ...
Page 392: ...392 V6100 and V7122 User Guide Reader s Notes ...
Page 409: ...V6100 and V7122 User Guide 409 Reader s Notes ...
Page 413: ...V6100 and V7122 User Guide 413 Reader s Notes ...
Page 425: ...V6100 and V7122 User Guide 425 Figure 145 UDP2File Utility Reader s Notes ...
Page 431: ...V6100 and V7122 User Guide 431 Reader s Notes ...
Page 447: ...V6100 and V7122 User Guide 447 Reader s Notes ...
Page 483: ...V6100 and V7122 User Guide 483 Reader s Notes ...