277
IPSec Commands
E-DOC-CTC-20040216-0002 v1.0
Available parameters
1. Supported Phase 1 Modes:
•
IDENTITY
•
AGGRESSIVE
The parameter is global: if specified, you can not have OR'ed proposals with a different Phase 1 Mode parameter.
2. DHGROUP: Supported OAKLEY group numbers for Diffie-Helman calculations
•
1 (768 bits)
•
2 (1024 bits)
•
5 (2048 bits).
Elliptic group curves are not supported.
3. Supported Phase 2 encapsulation protocols:
•
IPCOMP
•
AH
•
ESP.
A Phase 2 descriptor must contain either AH, ESP, or both. In case of ESP, an encryption algorithm must be specified;
in case of AH, the integrity algorithm (HMAC) and a hashing algorithm must be specified.
4. Supported encryption algorithms:
•
DES: The weakest of the algorithms and relatively slow, but industry standard. Key size=56 bits.
•
3DES: Stronger version of DES, but slowest of the algorithms. Key size=168 bits.
•
RC5: An RSA algorithm, both fast and strong. Supported valid key sizes=40-256 bits (default=128).
•
AES: Strong and fast new algorithm, favoured by cryptologists. Supported valid key sizes=128, 192, and 256
bits (default=128).
•
NULL: No encryption is used.
The encryption parameter is mandatory in a Phase 1 descriptor.
5. Supported Phase 2 SA compression: LZS
6. Supported integrity algorithm: HMAC.
The HMAC keyword is mandatory in a Phase 2 descriptor whenever a hash algorithm (MD5 or SHA1) is specified.
7.Supported hashing algorithms:
•
MD5
•
SHA1: Stronger than MD5, but slower.
8. Supported Lifetime:
•
MINUTES, SECONDS: real-time life time (allowed values between 5 and 525600 seconds).
•
KB: Maximum amount of KiloBytes (allowed values between 10 and 1073741824 KBytes)
Or, to specify an unlimited life time:
•
MINUTES FOREVER or SECONDS FOREVER or KB FOREVER
9. Additional/Optional statement parameters:
•
OR (Alternative descriptor proposals)
•
AND (SA bundle concept)
AND has priority over OR: the AND binding is stronger that the OR binding.
Summary of Contents for SpeedTouch 608
Page 1: ...SpeedTouch 608 Business DSL Routers CLI Reference Guide Release R4 2 7 600 SERIES...
Page 2: ......
Page 3: ...SpeedTouch 608 CLI Reference Guide Release R4 2 7...
Page 66: ...64 Bridge Commands E DOC CTC 20040216 0002 v1 0...
Page 84: ...82 Config Commands E DOC CTC 20040216 0002 v1 0...
Page 126: ...124 DHCP Commands E DOC CTC 20040216 0002 v1 0...
Page 170: ...168 ETHoA Commands E DOC CTC 20040216 0002 v1 0...
Page 234: ...232 IPoA Commands E DOC CTC 20040216 0002 v1 0...
Page 244: ...242 IPQoS Commands E DOC CTC 20040216 0002 v1 0...
Page 356: ...354 Phonebook Commands E DOC CTC 20040216 0002 v1 0...
Page 372: ...370 PPPoA Commands E DOC CTC 20040216 0002 v1 0...
Page 394: ...392 PPPoE Commands E DOC CTC 20040216 0002 v1 0...
Page 410: ...408 QoSBook Commands E DOC CTC 20040216 0002 v1 0...
Page 436: ...434 Software Commands E DOC CTC 20040216 0002 v1 0...
Page 444: ...442 Switch Commands E DOC CTC 20040216 0002 v1 0...
Page 454: ...452 System Commands E DOC CTC 20040216 0002 v1 0...
Page 460: ...458 Systemlog Commands E DOC CTC 20040216 0002 v1 0...
Page 468: ...466 UPnP Commands E DOC CTC 20040216 0002 v1 0...
Page 488: ...486 Supported Key Names E DOC CTC 20040216 0002 v1 0...
Page 489: ......