
IPSec
System Administrator’s Guide
83
Other options
The following options will become available on this page depending on what has been
configured previously:
•
Local Public Key field is the public part of the RSA key generated for RSA Digital
Signatures authentication. These fields are automatically populated and do not
need to be modified unless a different RSA key is to be used. This key must be
entered in the Remote Public Key field of the remote party's tunnel configuration.
This field appears when RSA Digital Signatures has been selected.
•
Remote Public Key field is the public part of the remote party's RSA Key
generated for RSA Digital Key authentication. This field must be populated with
the remote party's public RSA key. This field appears when RSA Digital
Signatures has been selected.
•
Modulus, Public Exponent, Private Exponent, Prime1, Prime2, Exponent1,
Exponent2 and Coefficient fields constitute the private part of the RSA key.
These fields are automatically populated and do not need to be modified unless a
different RSA key is to be used. This field appears when RSA Digital Signatures
has been selected.
•
Local Certificate pull down menu contains a list of the local certificates that have
been uploaded for X.509 authentication. Select the required certificate to be used
to negotiate the tunnel. This field appears when X.509 Certificates has been
selected.
Define phase 2 settings page
1
Set the length of time before Phase 2 is renegotiated in the
Key lifetime (m)
field. The length may vary between 1 and 1440 minutes. For most applications
60 minutes is recommended. For this example, leave the Key Lifetime as the
default value of 60 minutes.
2. Select a
Phase 2 Proposal
. Any combination of the ciphers, hashes and Diffie
Hellman groups that the Shiva VPN Gateway supports can be selected. The
supported ciphers are DES, 3DES and AES (128, 196 and 256 bits). The
supported hashes are MD5 and SHA and the supported Diffie Hellman group are
1 (768 bit), 2 (1024 bit) and 5 (1536 bits). The Shiva VPN Gateway also supports
extensions to the Diffie Hellman groups to include 2048, 3072 and 4096 bit
Oakley groups. Perfect Forward Secrecy is enabled if a Diffie-Hellman group or
an extension is chosen. Phase 2 can also have the option to not select a Diffie
Hellman Group, in this case Perfect Forward Secrecy is not enabled. Perfect
Forward Secrecy of keys provides greater security and is the recommended
setting. For this example, select the 3DES-SHA-Diffie Hellman Group 2 (1024
bit) option.
Summary of Contents for SHIVA 1100
Page 38: ...QoS traffic shaping 38 System Administrator s Guide...
Page 44: ...DHCP relay 44 System Administrator s Guide...
Page 66: ...Access control 66 System Administrator s Guide...
Page 122: ...Technical Support 122 System Administrator s Guide...
Page 132: ...132 System Administrator s Guide...