Model 9289
Spectracom Corporation
NetClock/NTP Network Time Provider Instruction Manual
3-94
Alternatively, you may generate elsewhere and upload to the NetClock your key pair(s). Specify
the directory and the name of the key pairs uploaded to it. Regardless of the method used,
however, you must upload the peer’s public key to the NetClock and provide the directory and
file name to the NetClock in the IPSec IKE SA Configuration screen.
3.4.20.6.2 IKE Phase 2 Configuration
Life Time
defines how long an IPSec SA will be used.
Encryption Algorithm
defines the group used for Diffie-Hellman exponentiations. This directive
must be defined using one of the following:
Group 1 - Modp768
Group 2 - Modp1024
Group 5 - Modp1536
Grouip 14 - Modp2048
NOTE:
When using Aggressive mode, the DH group defined for each proposal must be the
same.
Encryption Algorithm
specifies the algorithm used for Phase 2. Select DES, 3DES, AES (used
with ESP) or NULL as desired (or as required by your network administrator).
Authentication Algorithm
defines another algorithm used for Phase 2. Select HMAC-SHA1 or
HMAC-MD5 as desired or required.
Compression Algorithm
defaults to “deflate.” It is not configurable at this time.
NOTE:
After completing and submitting changes in the IPSec IKE SA Configuration screen,
check to make sure IPSec is enabled and IKE is selected for use with IPSec. The IKE
Log (refer to
Logs and Status Reporting
) is helpful in troubleshooting this condition.
3.4.20.6.3 Configure IPSec Security Policy
Configure the IPSec security policy from the IPSec General screen (Figure 3-82).
NOTE:
Always configure IKE BEFORE enabling the IKE option from the IPSec General
screen. If IKE is not configured, the IKE daemon won’t start correctly when the
Security Association is enabled.
From the IPSec General screen (Figure 3-82), enable (or disable) the IPSec service and specify
the Security Association (IKE if already configured, or Manually Configure). In the Security
Policy table, input the NetClock’s IP address as the Source IP and host A’s address as the
Destination IP.
Summary of Contents for 9289
Page 18: ...Model 9289 Spectracom Corporation NetClock NTP Network Time Provider Instruction Manual 1 8...
Page 36: ...Model 9289 Spectracom Corporation NetClock NTP Network Time Provider Instruction Manual 2 18...
Page 154: ...Model 9289 Spectracom Corporation NetClock NTP Network Time Provider Instruction Manual 3 118...