SA lifetime [s]
Number {180 – 86400}, default = 3600 s (1 hour)
Time of CHILD SA validity. The new key exchange or re-authentication is triggered immediately
the key expires. The true time of expiration is randomly selected within the range of 90-110%,
to prevent collision when the key exchange is triggered from both sides simultaneously.
The SA lifetime for CHILD SA is normally much shorter than SA lifetime for IKE SA because
the CHILD SA normally transfers much more data than IKE SA (key exchange only). Changing
the keys serves as protection against breaking the cypher by analyzing big amounts of data
encrypted by the same cypher.
Note
The M!DGE3 unit load is seriously affected when key exchange is in process.
PSK
PSK (Pre-shared key) authentication is used for IKE SA authentication. The relevant peer is identified
using it's "Peer ID". The key must be the same for both local and peer side of the IPsec.
Mode
List box {Passphrase; Key}, default = "Passphrase"
This parameter occurs only, if parameter "Encryption" is set to "AES-256-CCM".
Passphrase
The PSK key is entered as a password. Empty password is not allowed (max. length
is 128 characters). Passphrase must not contain any unsupported characters. Un-
supported characters are: ", `, \, $, ;.
Key
It is possible to set 256 bits long Key instead of Passphrase. This parameter occurs
only, if parameter
Mode
is set to "Key".
Peer Address
Default = 0.0.0.0
IKE peer IP address.
Local ID
IP address or FQDN (Fully Qualified Domain Name) is used as the Local side identification. It must
be the same as "Peer ID" of the IKE peer.
Peer ID
IP address or FQDN (Fully Qualified Domain Name) is used as the IKE peer identification. It must
be the same as "Local ID" of the IKE peer. The "Peer ID" must be unique in the whole table.
M!DGE3 Cellular Router – © RACOM s.r.o.
114
Settings