Version 6.6
137
MP-11x & MP-124
User's Manual
12. Security
•
Key exchange (DH): The DH protocol creates the master key. DH requires both
peers to agree on certain mathematical parameters, known as the "group".
•
Authentication: The two peers authenticate one another using a pre-shared key
configured in the IP Security Associations Table or by using certificate-based
authentication.
Quick Mode
(creates the encrypted IPSec tunnel once initial security is set up):
•
SA negotiation: An IPSec SA is created by negotiating encryption and
authentication capabilities using the same proposal mechanism as in Main mode.
•
Key exchange: A symmetrical key is created for encrypting IPSec traffic; the
peers communicate with each other in encrypted form, secured by the previously
negotiated "master" key.
IKE specifications summary:
Authentication methods: pre-shared key or certificate-based authentication
Main mode supported for IKE Phase 1
DH group 1 or group 2
Encryption algorithms: Data Encryption Standard (DES), Advanced Encryption
Standard (AES), and 3DES
Hash algorithms: SHA1 and MD5
IPSec is responsible for securing the IP traffic. This is accomplished by using the
Encapsulation Security Payload (ESP) protocol to encrypt (and decrypt) the IP payload.
This is configured in the IPSec Security Association table, which defines the IP peers to
which IPSec security is applied.
IPSec specifications summary:
Transport and Tunneling Mode
Encapsulation Security Payload (ESP) only
Encryption algorithms: AES, DES, and 3DES
Hash types: SHA1 and MD5
12.4.1 Enabling IPSec
To enable IKE and IPSec processing, you must enable the IPSec feature, as described
below.
To enable IPSec:
1.
Open the General Security Settings page (
Configuration
tab >
VoIP
menu >
Security
>
General Security Settings
).
Figure
12-3: Enabling IPSec
2.
Set the 'Enable IP Security' parameter to
Enable
.
3.
Click
Submit
, and then reset the device with a flash burn.
12.4.2 Configuring IP Security Proposal Table
The IP Security Proposal Table page is used to configure Internet Key Exchange (IKE) with
up to four proposal settings. Each proposal defines an encryption algorithm, an
authentication algorithm, and a Diffie-Hellman group identifier. The same set of proposals
applies to both Main mode and Quick mode.
Содержание Media Pack MP-124
Страница 2: ......
Страница 14: ...User s Manual 14 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 18: ...User s Manual 18 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 23: ...Part I Getting Started with Initial Connectivity...
Страница 24: ......
Страница 32: ...User s Manual 32 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 33: ...Part II Management Tools...
Страница 34: ......
Страница 36: ...User s Manual 36 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 86: ...User s Manual 86 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 88: ...User s Manual 88 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 93: ...Part III General System Settings...
Страница 94: ......
Страница 103: ...Part IV General VoIP Configuration...
Страница 104: ......
Страница 130: ...User s Manual 130 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 164: ...User s Manual 164 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 174: ...User s Manual 174 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 199: ...Part V Gateway Application...
Страница 200: ......
Страница 202: ...User s Manual 202 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 240: ...User s Manual 240 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 286: ...User s Manual 286 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 287: ...Part VI Stand Alone Survivability Application...
Страница 288: ......
Страница 296: ...User s Manual 296 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 319: ...Part VII Maintenance...
Страница 320: ......
Страница 326: ...User s Manual 326 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 359: ...Part VIII Status Performance Monitoring and Reporting...
Страница 360: ......
Страница 389: ...Part IX Diagnostics...
Страница 390: ......
Страница 404: ...User s Manual 404 Document LTRT 65422 MP 11x MP 124...
Страница 417: ...Part X Appendix...
Страница 418: ......
Страница 580: ...User s Manual 580 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 584: ...User s Manual Ver 6 6 www audiocodes com...