Version 6.6
161
MP-11x & MP-124
User's Manual
13. Security
5.
To save the changes to flash memory, see 'Saving Configuration' on page
Table
13-3: IP Security Proposals Table Configuration Parameters
Parameter Name
Description
Encryption Algorithm
[IPsecProposalTable_EncryptionAlgorithm]
Defines the encryption (privacy) algorithm.
[0]
NONE
[1]
DES CBC
[2]
3DES CBC
[3]
AES (default)
Authentication Algorithm
[IPsecProposalTable_AuthenticationAlgorithm]
Defines the message authentication (integrity)
algorithm.
[0]
NONE
[2]
HMAC SHA1 96
[4]
HMAC MD5 96 (default)
Diffie Hellman Group
[IPsecProposalTable_DHGroup]
Defines the length of the key created by the DH
protocol for up to four proposals. For the
ini
file
parameter,
X
denotes the proposal number (0 to
3).
[0]
Group 1 (768 Bits) = DH-786-Bit
[1]
Group 2 (1024 Bits) (default) = DH-1024-
Bit
If no proposals are defined, the default settings (shown in the following table) are applied.
Table
13-4: Default IPSec/IKE Proposals
Proposal
Encryption
Authentication
DH Group
Proposal 0
3DES
SHA1
Group 2 (1024 bit)
Proposal 1
3DES
MD5
Group 2 (1024 bit)
Proposal 2
3DES
SHA1
Group 1 (786 bit)
Proposal 3
3DES
MD5
Group 1 (786 bit)
13.4.3 Configuring IP Security Associations Table
The IP Security Associations Table page allows you to configure up to 20 peers (hosts or
networks) for IP security (IPSec)/IKE. Each of the entries in this table controls both Main
and Quick mode configuration for a single peer. Each row in the table refers to a different
IP destination. IPSec can be applied to all traffic to and from a specific IP address.
Alternatively, IPSec can be applied to a specific flow, specified by port (source or
destination) and protocol type.
The destination IP address (and optionally, destination port, source port and protocol type)
of each outgoing packet is compared to each entry in the table. If a match is found, the
device checks if an SA already exists for this entry. If no SA exists, the IKE protocol is
invoked and an IPSec SA is established and the packet is encrypted and transmitted. If a
match is not found, the packet is transmitted without encryption.
This table can also be used to enable Dead Peer Detection (RFC 3706), whereby the
device queries the liveliness of its IKE peer at regular intervals or on-demand. When two
peers communicate with IKE and IPSec, the situation may arise in which connectivity
between the two goes down unexpectedly. In such cases, there is often no way for IKE and
Содержание Media Pack MP-11x
Страница 2: ......
Страница 14: ...User s Manual 14 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 24: ...User s Manual 24 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 25: ...Part I Getting Started with Initial Connectivity...
Страница 26: ......
Страница 35: ...Part II Management Tools...
Страница 36: ......
Страница 38: ...User s Manual 38 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 86: ...User s Manual 86 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 94: ...User s Manual 94 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 100: ...User s Manual 100 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 108: ...User s Manual 108 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 109: ...Part III General System Settings...
Страница 110: ......
Страница 118: ...User s Manual 118 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 121: ...Part IV General VoIP Configuration...
Страница 122: ......
Страница 152: ...User s Manual 152 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 202: ...User s Manual 202 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 204: ...User s Manual 204 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 230: ...User s Manual 230 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 231: ...Part V Gateway Application...
Страница 232: ......
Страница 234: ...User s Manual 234 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 274: ...User s Manual 274 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 278: ...User s Manual 278 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 298: ...User s Manual 298 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 326: ...User s Manual 326 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 327: ...Part VI Stand Alone Survivability Application...
Страница 328: ......
Страница 336: ...User s Manual 336 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 358: ...User s Manual 358 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 361: ...Part VII Maintenance...
Страница 362: ......
Страница 368: ...User s Manual 368 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 406: ...User s Manual 406 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 409: ...Part VIII Status Performance Monitoring and Reporting...
Страница 410: ......
Страница 441: ...Part IX Diagnostics...
Страница 442: ......
Страница 456: ...User s Manual 456 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 458: ...User s Manual 458 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 471: ...Part X Appendix...
Страница 472: ......
Страница 650: ...International Headquarters Contact us www audiocodes com info Website www audiocodes com Document LTRT 65432...