Version 5.2
205
August 2007
SIP User's Manual
5. Web-based Management
3.
From the ‘Policy Index’ drop-down list, select the peer you want to edit (up to 20 peers
can be configured).
4.
Configure the IKE parameters according to the parameters described in the table
below. Up to two IKE main mode proposals (Encryption / Authentication / DH group
combinations) can be defined. The same proposals must be configured for all peers.
5.
Click
Create
; a row is create in the IKE table
6.
To save the changes to flash memory, refer to 'Saving Configuration' on page
238
.
To delete a peer from the IKE table, select it from the ‘Policy Index’ drop-down list, click the
button
Delete
, and then click
OK
at the prompt.
The parameters described in the following table are used to configure the first phase (main
mode) of the IKE negotiation for a specific peer. A different set of parameters can be
configured for each of the 20 available peers.
Table
5-43: IKE Table Configuration Parameters
Parameter Name
Description
Authentication Method
[IkePolicyAuthenticationM
ethod]
Determines the authentication method for IKE.
The valid authentication method values include:
[0]
Pre-shared Key (default)
[1]
RSA Signature
Notes:
For pre-shared key based authentication, peers participating in an
IKE exchange must have a prior (out-of-band) knowledge of the
common key (see IKEPolicySharedKey parameter).
For RSA signature based authentication, peers must be loaded with
a certificate signed by a common CA. For additional information on
certificates, refer to 'Server Certificate Replacement' on page
193
.
Shared Key
[IKEPolicySharedKey]
Determines the pre-shared key (in textual format).
Both peers must register the same pre-shared key for the
authentication process to succeed.
Notes:
The pre-shared key forms the basis of IPSec security and should
therefore be handled cautiously (in the same way as sensitive
passwords). It is not recommended to use the same pre-shared key
for several connections.
Since the
ini
file is in plain text format, loading it to the gateway over
a secure network connection is recommended, preferably over a
direct crossed-cable connection from a management PC. For added
confidentiality, use the encoded
ini
file option (described in 'Secured
ini File' on page
251
).
After it is configured, the value of the pre-shared key cannot be
obtained via Embedded Web Server,
ini
file, or SNMP (refer the
SIP
Series Reference Manual
).
IKE SA LifeTime (sec)
[IKEPolicyLifeInSec]
Determines the time (in seconds) the SA negotiated in the first IKE
session (main mode) is valid. After the time expires, the SA is re-
negotiated.
The default value is 28800 (8 hours).
Summary of Contents for Mediapack mp-11x
Page 1: ...Document LTRT 65409 August 2007 User s Manual Version 5 2...
Page 2: ......
Page 14: ...SIP User s Manual 14 Document LTRT 65409 MediaPack Series Reader s Notes...
Page 18: ...SIP User s Manual 18 Document LTRT 65409 MediaPack Series Reader s Notes...
Page 22: ...SIP User s Manual 22 Document LTRT 65409 MediaPack Series Reader s Notes...
Page 44: ...SIP User s Manual 44 Document LTRT 65409 MediaPack Series Reader s Notes...
Page 47: ...Version 5 2 47 August 2007 SIP User s Manual 4 Getting Started Figure 4 1 Startup Process...
Page 322: ...SIP User s Manual 322 Document LTRT 65409 MediaPack Series Reader s Notes...
Page 380: ...SIP User s Manual 380 Document LTRT 65409 MediaPack Series Reader s Notes...
Page 388: ...SIP User s Manual 388 Document LTRT 65409 MediaPack Series Reader s Notes...
Page 390: ...User s Manual Version 5 2 www audiocodes com...