Page 114 SonicWALL TELE3 SP Administrator’s Guide
client. The following encryption methods are available for Group VPN and are listed in order
from most secure to least secure:
-
Strong Encrypt and Authenticate (ESP 3DES HMAC SHA1)
-
Strong Encrypt and Authenticate (ESP 3DES HMAC MD5)
-
Strong Encrypt and Authenticate (ESP DES HMAC SHA1)
-
Strong Encrypt and Authenticate (ESP DES HMAC MD5)
•
If
IKE using Pre-shared Secret
is selected for the
IPSec Keying Mode
, the
Shared
Secret
field is displayed and you can type in your shared secret. If
Group VPN using
preshared secret
is selected, an alphanumeric key is automatically generated.
Security Policy Settings using Manual Key
Manual Key
is configured differently than
IKE using Pre-shared Secret
or
Group VPN
. It
requires an
Incoming
and
Outgoing Security Parameter Index (SPI)
as well as an
Encryption Key
and
Authentication Key
.
•
Incoming SPI
- Enter the Security Parameter Index (SPI) that the remote location
transmits to identify the Security Association used for the VPN Tunnel. The SPI may be up
to eight characters long and is comprised of hexadecimal characters. Valid hexadecimal
characters are "0" to "9", and "a" to "f" inclusive (0, 1, 2, 3, 4, 5, 6, 7, 8, 9, a, b, c, d, e,
f). The hexadecimal characters "0" to "ff" inclusive are reserved by the Internet Engineering
Task Force (IETF) and are not allowed for use as an SPI. These numbers are not accepted
by the SonicWALL when entered as an SPI; an error message is displayed at the bottom of
the Web browser window when
Update
is pressed. For example, a valid SPI would be
1234abcd.
•
Outgoing SPI
- Enter the Security Parameter Index (SPI) that the local SonicWALL
transmits to identify the Security Association used for the VPN Tunnel. The SPI may be up
to eight characters long and is comprised of hexadecimal characters. Valid hexadecimal
characters are "0" to "9", and "a" to "f" inclusive (0, 1, 2, 3, 4, 5, 6, 7, 8, 9, a, b, c, d, e,
f). The hexadecimal characters "0" to "ff" inclusive are reserved by the Internet Engineering
Task Force (IETF) and are not allowed for use as an SPI. These numbers are not accepted
by the SonicWALL when entered as an SPI; an error message is displayed at the bottom of
the Web browser window when
Update
is pressed. For example, a valid SPI would be
1234abcd.
Note
: A Security Association's SPI must be unique when compared to SPIs used in other
Security Associations. However, a Security Association's
Incoming SPI
may be the same as
the
Outgoing SPI
.