SIP-2
77/145
USER GUIDE - Rev. 3 (January 2018)
Preshared Keys:
•
Peer IP.
This establishes the IP address of the remote tunnel equipment (
Remote
GW
) for which the password of the next parameter is defined.
•
Password
. The password is stored in this parameter.
•
Enable.
This indicates whether the configured password can be used (active
option) or not (inactive option).
IPSec Security Associations:
•
Transform set.
This identifies the set of parameters being configured to establish
an
IPSec Security association
so that it can be used by one or more configured
tunnels.
•
Protocol.
The protocol establishes which of the two types of encapsulation will be
used.
ESP
(Encapsulating Security Payload) provides ciphering and authentication
for each packet, and
AH
(Authentication Header) only provides the authentication
service.
•
Cipher alg.
This determines the cipher algorithm to be used for encrypting the user
data. The available algorithms are
DES
,
3DES
and
AES
.
•
Hash alg.
This determines the hash algorithm used for authentication. The
available options are
MD5
(Message Digest 5) and
SHA1
(Secure Hash Algorithm).
A third option exists,
non-auth,
which means the authentication is not included.
The authentication and ciphering options can be combined in different modes. If the
AH
protocol is selected, only the hash algorithm choice will be taken into account, and on
the contrary if the
ESP
protocol is selected, the encryption is always present with the
cipher algorithm selected, and the authentication may be included with either
MD5
or
SHA1,
or it may not be included if the
non-auth
value is selected.
•
PFS (Perfect Forward Secret).
If the option is enabled, this means that each new
code renegotiated must be completely separated from the previous one. The
remote end must accept the
PFS
option for the establishment to be successful.
This option provides additional security but a greater processing load.
•
Lifetime.
The maximum validity time for a security association. When the
established time is up, a new association is renegotiated. The value establishes the
time in seconds.