User's Manual
150
Document #: LTRT-89729
Mediant 3000
IKE is used to obtain the Security Associations (SA) between peers (the device and the
application it’s trying to contact). The SA contains the encryption keys and profile used by
IPSec to encrypt the IP stream. IKE negotiation comprises the following two phases:
Main Mode
(creates a secured channel for the Quick mode by obtaining a "master"
encryption key, without any prior keys, and authenticates the peers to each other):
•
SA negotiation: The peers negotiate their capabilities using up to four proposals.
Each proposal includes the Encryption method, Authentication algorithm, and the
Diffie-Hellman (DH) group. The master key’s lifetime is also negotiated.
•
Key exchange (DH): The DH protocol creates the master key. DH requires both
peers to agree on certain mathematical parameters, known as the "group".
•
Authentication: The two peers authenticate one another using a pre-shared key
configured in the IP Security Associations Table or by using certificate-based
authentication.
Quick Mode
(creates the encrypted IPSec tunnel once initial security is set up):
•
SA negotiation: An IPSec SA is created by negotiating encryption and
authentication capabilities using the same proposal mechanism as in Main mode.
•
Key exchange: A symmetrical key is created for encrypting IPSec traffic; the
peers communicate with each other in encrypted form, secured by the previously
negotiated "master" key.
IKE specifications summary:
Authentication methods: pre-shared key or certificate-based authentication
Main mode supported for IKE Phase 1
DH group 1 or group 2
Encryption algorithms: Data Encryption Standard (DES), Advanced Encryption
Standard (AES), and 3DES
Hash algorithms: SHA1 and MD5
IPSec is responsible for securing the IP traffic. This is accomplished by using the
Encapsulation Security Payload (ESP) protocol to encrypt (and decrypt) the IP payload.
This is configured in the IPSec Security Association table, which defines the IP peers to
which IPSec security is applied.
IPSec specifications summary:
Transport and Tunneling Mode
Encapsulation Security Payload (ESP) only
Encryption algorithms: AES, DES, and 3DES
Hash types: SHA1 and MD5
12.3.1 Enabling IPSec
To enable IKE and IPSec processing, you must enable the IPSec feature, as described
below.
To enable IPSec:
1.
Open the General Security Settings page (Configuration tab > VoIP menu > Security >
General Security Settings).
Figure
12-3: Enabling IPSec
2.
Set the 'Enable IP Security' parameter to Enable.
3.
Click Submit, and then reset the device with a flash burn.
Содержание Mediant 3000
Страница 1: ...User s Manual Version 6 6 Enterprise Session Border Controller VoIP Digital Media Gateway Mediant 3000...
Страница 2: ......
Страница 21: ...Version 6 6 21 Mediant 3000 User s Manual 1 Overview Figure 1 2 Mediant 3000 TP 6310 Functional Block Diagram...
Страница 22: ...User s Manual 22 Document LTRT 89729 Mediant 3000 Figure 1 3 Mediant 3000 TP 8410 Functional Block Diagram...
Страница 26: ...User s Manual 26 Document LTRT 89729 Mediant 3000 Reader s Note...
Страница 27: ...Part I Getting Started with Initial Connectivity...
Страница 28: ......
Страница 40: ...User s Manual 40 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 41: ...Part II Management Tools...
Страница 42: ......
Страница 44: ...User s Manual 44 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 80: ...User s Manual 80 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 98: ...User s Manual 98 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 103: ...Part III General System Settings...
Страница 104: ......
Страница 113: ...Part IV General VoIP Configuration...
Страница 114: ......
Страница 144: ...User s Manual 144 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 164: ...User s Manual 164 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 222: ...User s Manual 222 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 224: ...User s Manual 224 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 275: ...Part V Gateway and IP to IP Application...
Страница 276: ......
Страница 278: ...User s Manual 278 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 399: ...Part VI Session Border Controller Application...
Страница 400: ......
Страница 402: ...User s Manual 402 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 464: ...User s Manual 464 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 465: ...Part VII Stand Alone Survivability Application...
Страница 466: ......
Страница 474: ...User s Manual 474 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 494: ...User s Manual 494 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 497: ...Part VIII IP Media Capabilities...
Страница 498: ......
Страница 501: ...Part IX High Availability System...
Страница 502: ......
Страница 515: ...Part X Maintenance...
Страница 516: ......
Страница 522: ...User s Manual 522 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 524: ...User s Manual 524 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 552: ...User s Manual 552 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 562: ...User s Manual 562 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 565: ...Part XI Status Performance Monitoring and Reporting...
Страница 566: ......
Страница 578: ...User s Manual 578 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 609: ...Part XII Diagnostics...
Страница 610: ......
Страница 624: ...User s Manual 624 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 626: ...User s Manual 626 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 638: ...User s Manual 638 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 639: ...Part XIII Appendix...
Страница 640: ......
Страница 864: ...User s Manual 864 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 871: ...Version 6 6 871 Mediant 3000 User s Manual 55 Selected Technical Specifications Reader s Notes...
Страница 872: ...User s Manual Ver 6 6 www audiocodes com...