108
Function Specification
|
Source address specification
Fixed setting
Peer
1
IKEv1
extension
IKE SA deletion
Manual deletion
IKE SA deletion when “delete payload” is received
“delete payload” transmission when IKE SA is deleted
Rekey extension of IPsec SA/IKE SA
Continuous connection
Continuous connection
without traffic
On-demand connection
Rekey with traffic
There is traffic, but
rekey is not done
INITIAL-CONTACT setting
Single transmission (No additional payload)
Keepalive
DPD
Transmission interval
specification
Retry out frequency
specification
NAT traversal
1 session
Commit bit
Phase1: Aggressive mode only
Phase2: Responder only
IKEv2
Key exchange method
Automatic key (Key exchange protocol: IKEv2)
Authentication scheme
Pre-shared key method (pre-shared key)
Electronic certificate
EAP-MD5
Digital signature (site
only)
Supported
Algorithm
Encryption
3DES, AES-128, AES-192, AES-256
Authentication
HMAC-MD5, HMAC-SHA-1, HMAC-SHA-2-256
PRF
HMAC-MD5, HMAC-SHA-1, HMAC-SHA-2-256
DH group
768bit (group1), 1024bit (group2), 1536bit (group5),
2048bit (group14)
SA
IKE authentication
Local ID, remote ID
(IPv4 address, FQDN, Key-ID, and user-FQDN)
IKE connection
Retransmission interval specification, retransmission
frequency specification
Lifetime
Time setting
Rekey timing
Remaining time setting