
V7122 Gateway User Guide
337
Parameter Name
Description
Authentication Method
[IkePolicyAuthenticationMeth
od]
Determines the authentication method for IKE.
The valid authentication method values include:
0 = Pre-shared Key (default)
1 = RSA Signiture
For pre-shared key based authentication, peers participating
in an IKE exchange must have a prior (out-of-band)
knowledge of the common key (see IKEPolicySharedKey
parameter).
For RSA signature based authentication, peers must be
loaded with a certificate signed by a common CA. For
additional information on certificates, , see
Server Certificate
Replacement
.
IKE SA LifeTime (sec)
[IKEPolicyLifeInSec]
Determines the time (in seconds) the SA negotiated in the first IKE session
(main mode) is valid. After the time expires, the SA is re-negotiated.
The default value is 28800 (8 hours).
IKE SA LifeTime (KB)
[IKEPolicyLifeInKB]
Determines the lifetime (in kilobytes) the SA negotiated in the first IKE
session (main mode) is valid. After this size is reached, the SA is re-
negotiated.
The default value is 0 (this parameter is ignored).
The lifetime parameters (IKEPolicyLifeInSec and IKEPolicyLifeInKB) determine the duration the SA created
in the main mode phase is valid. When the lifetime of the SA expires, it is automatically renewed by
performing the IKE first phase negotiations. To refrain from a situation where the SA expires, a new SA is
being negotiated while the old one is still valid. As soon as the new SA is created, it replaces the old one.
This procedure occurs whenever an SA is about to expire.
If no IKE methods are defined (Encryption / Authentication / DH Group), the default settings
(shown in
Table 69
) are applied.
Table 69
Default IKE First Phase Proposals
Encryption
Authentication
DH
Group
Proposal 0
3DES
SHA1
1024
Proposal 1
3DES
MD5
1024
Proposal 2
3DES
SHA1
786
Proposal 3
3DES
MD5
786
To configure the IKE table using the
ini
file:
The IKE parameters are configured using
ini
file tables (described in
Using Parameter
Tables
). Each line in the table refers to a different IKE peer.
The Format line (IKE_DB_INDEX in the example below) specifies the order in which the
actual data lines are written. The order of the parameters is irrelevant. Parameters are not
mandatory unless stated otherwise. To support more than one Encryption / Authentication /
Содержание VCX V7122
Страница 28: ...28 V7122 GatewayUser Guide ...
Страница 39: ...V7122 Gateway User Guide 39 Reader s Notes ...
Страница 40: ...40 V7122 GatewayUser Guide ...
Страница 58: ...58 V7122 GatewayUser Guide Reader s Notes ...
Страница 66: ...66 V7122 GatewayUser Guide Reader s Notes ...
Страница 144: ...144 V7122 GatewayUser Guide Reader s Notes ...
Страница 239: ...V7122 Gateway User Guide 239 Reader s Notes ...
Страница 240: ...240 V7122 GatewayUser Guide ...
Страница 246: ...246 V7122 GatewayUser Guide Reader s Notes ...
Страница 270: ...270 V7122 GatewayUser Guide Reader s Notes ...
Страница 287: ...V7122 Gateway User Guide 287 Reader s Notes ...
Страница 288: ...288 V7122 GatewayUser Guide ...
Страница 294: ...294 V7122 GatewayUser Guide Reader s Notes ...
Страница 300: ...300 V7122 GatewayUser Guide Figure 88 Gateway s Startup Process ...
Страница 315: ...V7122 Gateway User Guide 315 Reader s Notes ...
Страница 316: ...316 V7122 GatewayUser Guide ...
Страница 332: ...332 V7122 GatewayUser Guide Reader s Notes ...
Страница 358: ...358 V7122 GatewayUser Guide Reader s Notes ...
Страница 362: ...362 V7122 GatewayUser Guide Reader s Notes ...
Страница 389: ...V7122 Gateway User Guide 389 Reader s Notes ...
Страница 390: ...390 V7122 GatewayUser Guide ...
Страница 398: ...398 V7122 GatewayUser Guide Reader s Notes ...
Страница 406: ...406 V7122 GatewayUser Guide Reader s Notes ...
Страница 408: ...408 V7122 GatewayUser Guide Reader s Notes ...
Страница 409: ...V7122 Gateway User Guide 409 ...
Страница 419: ...V7122 Gateway User Guide 419 Reader s Notes ...
Страница 437: ...V7122 Gateway User Guide 437 Reader s Notes ...
Страница 452: ...452 V7122 GatewayUser Guide Figure 137 UDP2File Utility ...
Страница 453: ...V7122 Gateway User Guide 453 Reader s Notes ...
Страница 459: ...V7122 Gateway User Guide 459 Reader s Notes ...
Страница 475: ...V7122 Gateway User Guide 475 ...