Version 6.6
139
MP-11x & MP-124
User's Manual
12. Security
If no proposals are defined, the default settings (shown in the following table) are applied.
Table
12-4: Default IPSec/IKE Proposals
Proposal
Encryption
Authentication
DH Group
Proposal 0
3DES
SHA1
Group 2 (1024 bit)
Proposal 1
3DES
MD5
Group 2 (1024 bit)
Proposal 2
3DES
SHA1
Group 1 (786 bit)
Proposal 3
3DES
MD5
Group 1 (786 bit)
12.4.3 Configuring IP Security Associations Table
The IP Security Associations Table page allows you to configure up to 20 peers (hosts or
networks) for IP security (IPSec)/IKE. Each of the entries in this table controls both Main
and Quick mode configuration for a single peer. Each row in the table refers to a different
IP destination. IPSec can be applied to all traffic to and from a specific IP address.
Alternatively, IPSec can be applied to a specific flow, specified by port (source or
destination) and protocol type.
The destination IP address (and optionally, destination port, source port and protocol type)
of each outgoing packet is compared to each entry in the table. If a match is found, the
device checks if an SA already exists for this entry. If no SA exists, the IKE protocol is
invoked and an IPSec SA is established and the packet is encrypted and transmitted. If a
match is not found, the packet is transmitted without encryption.
This table can also be used to enable Dead Peer Detection (RFC 3706), whereby the
device queries the liveliness of its IKE peer at regular intervals or on-demand. When two
peers communicate with IKE and IPSec, the situation may arise in which connectivity
between the two goes down unexpectedly. In such cases, there is often no way for IKE and
IPSec to identify the loss of peer connectivity. As such, the Security Associations (SA)
remain active until their lifetimes naturally expire, resulting in a "black hole" situation where
both peers discard all incoming network traffic. This situation may be resolved by
performing periodic message exchanges between the peers. When no reply is received,
the sender assumes SA’s are no longer valid on the remote peer and attempts to
renegotiate.
Notes:
•
Incoming packets whose parameters match one of the entries in the IP
Security Associations table but is received without encryption, is rejected.
•
If you change the device's IP address on-the-fly, you must then reset the
device for IPSec to function properly.
•
The proposal list must be contiguous.
•
For security, once the IKE pre-shared key is configured, it is not
displayed in any of the device's management tools.
•
You can also configure the IP Security Associations table using the table
ini file parameter IPsecSATable (see 'Security Parameters' on page
446
).
Содержание Media Pack MP-124
Страница 2: ......
Страница 14: ...User s Manual 14 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 18: ...User s Manual 18 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 23: ...Part I Getting Started with Initial Connectivity...
Страница 24: ......
Страница 32: ...User s Manual 32 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 33: ...Part II Management Tools...
Страница 34: ......
Страница 36: ...User s Manual 36 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 86: ...User s Manual 86 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 88: ...User s Manual 88 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 93: ...Part III General System Settings...
Страница 94: ......
Страница 103: ...Part IV General VoIP Configuration...
Страница 104: ......
Страница 130: ...User s Manual 130 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 164: ...User s Manual 164 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 174: ...User s Manual 174 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 199: ...Part V Gateway Application...
Страница 200: ......
Страница 202: ...User s Manual 202 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 240: ...User s Manual 240 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 286: ...User s Manual 286 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 287: ...Part VI Stand Alone Survivability Application...
Страница 288: ......
Страница 296: ...User s Manual 296 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 319: ...Part VII Maintenance...
Страница 320: ......
Страница 326: ...User s Manual 326 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 359: ...Part VIII Status Performance Monitoring and Reporting...
Страница 360: ......
Страница 389: ...Part IX Diagnostics...
Страница 390: ......
Страница 404: ...User s Manual 404 Document LTRT 65422 MP 11x MP 124...
Страница 417: ...Part X Appendix...
Страница 418: ......
Страница 580: ...User s Manual 580 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Страница 584: ...User s Manual Ver 6 6 www audiocodes com...