Version 6.6
161
MP-11x & MP-124
User's Manual
13. Security
5.
To save the changes to flash memory, see 'Saving Configuration' on page
Table
13-3: IP Security Proposals Table Configuration Parameters
Parameter Name
Description
Encryption Algorithm
[IPsecProposalTable_EncryptionAlgorithm]
Defines the encryption (privacy) algorithm.
[0]
NONE
[1]
DES CBC
[2]
3DES CBC
[3]
AES (default)
Authentication Algorithm
[IPsecProposalTable_AuthenticationAlgorithm]
Defines the message authentication (integrity)
algorithm.
[0]
NONE
[2]
HMAC SHA1 96
[4]
HMAC MD5 96 (default)
Diffie Hellman Group
[IPsecProposalTable_DHGroup]
Defines the length of the key created by the DH
protocol for up to four proposals. For the
ini
file
parameter,
X
denotes the proposal number (0 to
3).
[0]
Group 1 (768 Bits) = DH-786-Bit
[1]
Group 2 (1024 Bits) (default) = DH-1024-
Bit
If no proposals are defined, the default settings (shown in the following table) are applied.
Table
13-4: Default IPSec/IKE Proposals
Proposal
Encryption
Authentication
DH Group
Proposal 0
3DES
SHA1
Group 2 (1024 bit)
Proposal 1
3DES
MD5
Group 2 (1024 bit)
Proposal 2
3DES
SHA1
Group 1 (786 bit)
Proposal 3
3DES
MD5
Group 1 (786 bit)
13.4.3 Configuring IP Security Associations Table
The IP Security Associations Table page allows you to configure up to 20 peers (hosts or
networks) for IP security (IPSec)/IKE. Each of the entries in this table controls both Main
and Quick mode configuration for a single peer. Each row in the table refers to a different
IP destination. IPSec can be applied to all traffic to and from a specific IP address.
Alternatively, IPSec can be applied to a specific flow, specified by port (source or
destination) and protocol type.
The destination IP address (and optionally, destination port, source port and protocol type)
of each outgoing packet is compared to each entry in the table. If a match is found, the
device checks if an SA already exists for this entry. If no SA exists, the IKE protocol is
invoked and an IPSec SA is established and the packet is encrypted and transmitted. If a
match is not found, the packet is transmitted without encryption.
This table can also be used to enable Dead Peer Detection (RFC 3706), whereby the
device queries the liveliness of its IKE peer at regular intervals or on-demand. When two
peers communicate with IKE and IPSec, the situation may arise in which connectivity
between the two goes down unexpectedly. In such cases, there is often no way for IKE and
Summary of Contents for Media Pack MP-11x
Page 2: ......
Page 14: ...User s Manual 14 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 24: ...User s Manual 24 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 25: ...Part I Getting Started with Initial Connectivity...
Page 26: ......
Page 35: ...Part II Management Tools...
Page 36: ......
Page 38: ...User s Manual 38 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 86: ...User s Manual 86 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 94: ...User s Manual 94 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 100: ...User s Manual 100 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 108: ...User s Manual 108 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 109: ...Part III General System Settings...
Page 110: ......
Page 118: ...User s Manual 118 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 121: ...Part IV General VoIP Configuration...
Page 122: ......
Page 152: ...User s Manual 152 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 202: ...User s Manual 202 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 204: ...User s Manual 204 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 230: ...User s Manual 230 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 231: ...Part V Gateway Application...
Page 232: ......
Page 234: ...User s Manual 234 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 274: ...User s Manual 274 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 278: ...User s Manual 278 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 298: ...User s Manual 298 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 326: ...User s Manual 326 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 327: ...Part VI Stand Alone Survivability Application...
Page 328: ......
Page 336: ...User s Manual 336 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 358: ...User s Manual 358 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 361: ...Part VII Maintenance...
Page 362: ......
Page 368: ...User s Manual 368 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 406: ...User s Manual 406 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 409: ...Part VIII Status Performance Monitoring and Reporting...
Page 410: ......
Page 441: ...Part IX Diagnostics...
Page 442: ......
Page 456: ...User s Manual 456 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 458: ...User s Manual 458 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 471: ...Part X Appendix...
Page 472: ......