
328
V6100 and V7122 User Guide
IKE Configuration
The parameters described in
Table 74
are used to configure the first phase (main mode) of
the IKE negotiation for a specific peer. A different set of parameters can be configured for
each of the 20 available peers.
(V6100 only) Up to two IKE main mode proposals (Encryption / Authentication / DH group
combinations) can be defined. The same proposals must be configured for all peers.
Table 74
IKE Table Configuration Parameters
Parameter Name
Description
Shared Key
[IKEPolicySharedKey]
Determines the pre-shared key (in textual format).
Both peers must register the same pre-shared key for the authentication
process to succeed.
The pre-shared key forms the basis of IPSec security and should
therefore be handled cautiously (in the same way as sensitive
passwords). It is not recommended to use the same pre-shared
key for several connections.
Since the ini file is in plain text format, loading it to the gateway
over a secure network connection is recommended, preferably
over a direct crossed-cable connection from a management PC.
For added confidentiality, use the encoded ini file option
(described in
Secured ini File
).
After it is configured, the value of the pre-shared key cannot be
obtained via Web, ini file or SNMP (see
IPSec and IKE
Configuration Table’s Confidentiality
).
First to Fourth Proposal
Encryption Type
[IKEPolicyProposalEncryptio
n_X]
Determines the encryption type used in the main mode negotiation for up to
four proposals.
X stands for the proposal number (0 to 3).
The valid encryption values are:
Not Defined (default)
DES-CBC
[1]
Triple DES-CBC
[2]
First to Fourth Proposal
Authentication Type
[IKEPolicyProposalAuthentic
ation_X]
Determines the authentication protocol used in the main mode negotiation
for up to four proposals.
X stands for the proposal number (0 to 3).
The valid authentication values are:
Not Defined (default)
HMAC-SHA1-96)
[2]
HMAC-MD5-96
[4]
First to Fourth Proposal DH
Group
[IKEPolicyProposalDHGroup
_X]
Determines the length of the key created by the DH protocol for up to four
proposals.
X stands for the proposal number (0 to 3).
The valid DH Group values are:
Not Defined
(default)
DH-786-Bit
[0]
DH-1024-Bit
[1]
Содержание V6100
Страница 28: ...28 V6100 and V7122 User Guide Reader s Notes...
Страница 48: ...48 V6100 and V7122 User Guide Reader s Notes...
Страница 72: ...72 V6100 and V7122 User Guide Reader s Notes...
Страница 80: ...80 V6100 and V7122 User Guide Reader s Notes...
Страница 151: ...V6100 and V7122 User Guide 151 Figure 83 Log off Prompt 2 Click OK in the prompt the Web session is logged off...
Страница 152: ...152 V6100 and V7122 User Guide Reader s Notes...
Страница 262: ...262 V6100 and V7122 User Guide Reader s Notes...
Страница 284: ...284 V6100 and V7122 User Guide Reader s Notes...
Страница 291: ...V6100 and V7122 User Guide 291 Figure 95 V7122 Startup Process...
Страница 324: ...324 V6100 and V7122 User Guide Reader s Notes...
Страница 354: ...354 V6100 and V7122 User Guide Reader s Notes...
Страница 374: ...374 V6100 and V7122 User Guide Reader s Notes...
Страница 382: ...382 V6100 and V7122 User Guide Figure 130 Example of a User Information File Reader s Notes...
Страница 392: ...392 V6100 and V7122 User Guide Reader s Notes...
Страница 409: ...V6100 and V7122 User Guide 409 Reader s Notes...
Страница 413: ...V6100 and V7122 User Guide 413 Reader s Notes...
Страница 425: ...V6100 and V7122 User Guide 425 Figure 145 UDP2File Utility Reader s Notes...
Страница 431: ...V6100 and V7122 User Guide 431 Reader s Notes...
Страница 447: ...V6100 and V7122 User Guide 447 Reader s Notes...
Страница 449: ...V6100 and V7122 User Guide 449 Figure 146 Connection Module CM Figure 147 OSN Server Figure 148 Hard Drive Module HDMX...
Страница 483: ...V6100 and V7122 User Guide 483 Reader s Notes...