
VITRIKO
Mobile Data Experts
1. CONFIGURATION OVER WEB BROWSER
Continued from previous page
Item
Description
Encapsulation Mode
IPsec mode (according to the method of encapsulation) – You
can choose
tunnel
(entire IP datagram is encapsulated) or
trans-
port
(only IP header).
NAT traversal
If address translation is used between two end points of the tun-
nel, it needs to enable
NAT Traversal
.
IKE Mode
Defines mode for establishing connection (
main
or
aggressive
).
If the aggressive mode is selected, establishing of IPsec tunnel
will be faster, but encryption will set permanently on 3DES-MD5.
IKE Algorithm
Way of algorithm selection:
•
auto
– encryption and hash alg. are selected automatically
•
manual
– encryption and hash alg. are defined by the user
IKE Encryption
Encryption algorithm – 3DES, AES128, AES192, AES256
IKE Hash
Hash algorithm – MD5 nebo SHA1
IKE DH Group
Diffie-Hellman groups determine the strength of the key used in
the key exchange process. Higher group numbers are more se-
cure, but require additional time to compute the key. Group with
higher number provides more security, but requires more pro-
cessing time.
ESP Algorithm
Way of algorithm selection:
•
auto
– encryption and hash alg. are selected automatically
•
manual
– encryption and hash alg. are defined by the user
ESP Encryption
Encryption algorithm – DES, 3DES, AES128, AES192, AES256
ESP Hash
Hash algorithm – MD5 nebo SHA1
PFS
Ensures that derived session keys are not compromised if one of
the private keys is compromised in the future
PFS DH Group
Diffie-Hellman group number (see
IKE DH Group
)
Key Lifetime
Lifetime key data part of tunnel. The minimum value of this pa-
rameter is 60 s. The maximum value is 86400 s.
IKE Lifetime
Lifetime key service part of tunnel. The minimum value of this
parameter is 60 s. The maximum value is 86400 s.
Rekey Margin
Specifies how long before connection expiry should attempt to
negotiate a replacement begin. Maximum value must be less
than half of IKE and Key Lifetime parameters.
Continued on next page
53
Contact www.vitriko.com [email protected]