Spectracom Corporation
Model 9289
NetClock/NTP Network Time Provider Instruction Manual
3-93
DH group
defines the group used for Diffie-Hellman exponentiations. This directive must be
defined using one of the following:
Group 1 - Modp768
Group 2 - Modp1024
Group 5 - Modp1536
Grouip 14 - Modp2048
NOTE:
When using Aggressive mode, the DH group defined for each proposal must be the
same.
Encryption Algorithm
specifies the algorithm used for Phase 1 negotiation. Choose DES,
3DES, or AES as desired (or as specified by your network administrator).
Hash Algorithm
defines another algorithm used for Phase 1 negotiation. Select HMAC-MD5 or
HMAC-SHA1 as desired or required.
Authentication Method
defines the means of Phase 1 authentication used (preshared keys or
X.509 certificates).
Preshared Keys
The easiest way to authenticate using the IKE daemon is through preshared keys. These keys
must be defined in a file uploaded to the location specified in the
Using Preshared key located in
field.
NOTE:
After the file is uploaded, its file privileges will be changed automatically to deny
unauthorized users access to the preshared keys. This means you will not be able to
access the file after uploading it. Always keep an extra copy of the file on hand in
another location.
The preshared key file should have the following syntax:
192.168.2.100
password1
5.0.0.1
password2
3ffe:501:ffff::3 password3
This file is organized in columns. The first column holds the identity of the peer authenticated by
the preshared key. The second column contains the keys.
X.509 Certificates
The IKE daemon supports the use of X.509 certificates for authentication. Spectram supplies
two means of providing the public/private key pair to the Netclock.
The first approach is through the user interface on the IPSec IKE SA Configuration screen.
Specify the Certificate Files Path and Peer’s Certificate File name, then select Md5 or Sha1 to
specify the Signature Algorithm. You must also specify the RSA Private Key Length to use when
generating the key pair.
Summary of Contents for 9289
Page 18: ...Model 9289 Spectracom Corporation NetClock NTP Network Time Provider Instruction Manual 1 8...
Page 36: ...Model 9289 Spectracom Corporation NetClock NTP Network Time Provider Instruction Manual 2 18...
Page 154: ...Model 9289 Spectracom Corporation NetClock NTP Network Time Provider Instruction Manual 3 118...