Prestige 662HW Series User’s Guide
VPN Screens
16-13
Figure 16-6 Two Phases to Set Up the IPSec SA
In phase 1 you must:
Choose a negotiation mode.
Authenticate the connection by entering a pre-shared key.
Choose an encryption algorithm.
Choose an authentication algorithm.
Choose a Diffie-Hellman public-key cryptography key group (
DH1
or
DH2
)
.
Set the IKE SA lifetime. This field allows you to determine how long an IKE SA should
stay up before it times out. An IKE SA times out when the IKE SA lifetime period
expires. If an IKE SA times out when an IPSec SA is already established, the IPSec SA
stays connected.
In phase 2 you must:
Choose which protocol to use (
ESP
or
AH
) for the IKE key exchange.
Choose an encryption algorithm.
Choose an authentication algorithm
Choose whether to enable Perfect Forward Secrecy (PFS) using Diffie-Hellman public-
key cryptography – see
section 16.11.3
None
(the default) to disable PFS.
Choose
Tunnel
mode or
Transport
mode.
Set the IPSec SA lifetime. This field allows you to determine how long the IPSec SA
should stay up before it times out. The Prestige automatically renegotiates the IPSec SA if
there is traffic when the IPSec SA lifetime period expires. The Prestige also automatically
renegotiates the IPSec SA if both IPSec routers have keep alive enabled, even if there is
no traffic. If an IPSec SA times out, then the IPSec router must renegotiate the SA the
next time someone attempts to send traffic.
16.11.1 Negotiation
Mode
The phase 1
Negotiation Mode
you select determines how the Security Association (SA) will be
established for each connection through IKE negotiations.
Main Mode
ensures the highest level of security when the communicating parties are
negotiating authentication (phase 1). It uses 6 messages in three round trips: SA
negotiation, Diffie-Hellman exchange and an exchange of nonces (a nonce is a random
Summary of Contents for Prestige 662HW Series
Page 26: ......
Page 28: ......
Page 36: ......
Page 54: ......
Page 56: ......
Page 64: ......
Page 84: ......
Page 100: ......
Page 116: ......
Page 128: ......
Page 150: ......
Page 154: ......
Page 162: ......
Page 168: ......
Page 194: ......
Page 196: ......
Page 200: ......
Page 208: ......
Page 214: ......
Page 216: ......
Page 230: ......
Page 242: ......
Page 244: ......
Page 252: ......
Page 258: ......
Page 262: ......
Page 266: ......
Page 272: ......
Page 286: ......
Page 290: ......
Page 310: ......
Page 328: ......
Page 352: ......
Page 358: ......
Page 362: ......
Page 374: ......
Page 376: ......
Page 394: ......
Page 398: ......
Page 400: ......
Page 410: ......
Page 444: ......
Page 452: ......