User's Manual
152
Document #: LTRT-89729
Mediant 3000
If no proposals are defined, the default settings (shown in the following table) are applied.
Default IPSec/IKE Proposals
Proposal
Encryption
Authentication
DH Group
Proposal 0
3DES
SHA1
Group 2 (1024 bit)
Proposal 1
3DES
MD5
Group 2 (1024 bit)
Proposal 2
3DES
SHA1
Group 1 (786 bit)
Proposal 3
3DES
MD5
Group 1 (786 bit)
12.3.3 Configuring IP Security Associations Table
The IP Security Associations Table page allows you to configure up to 20 peers (hosts or
networks) for IP security (IPSec)/IKE. Each of the entries in this table controls both Main
and Quick mode configuration for a single peer. Each row in the table refers to a different
IP destination. IPSec can be applied to all traffic to and from a specific IP address.
Alternatively, IPSec can be applied to a specific flow, specified by port (source or
destination) and protocol type.
The destination IP address (and optionally, destination port, source port and protocol type)
of each outgoing packet is compared to each entry in the table. If a match is found, the
device checks if an SA already exists for this entry. If no SA exists, the IKE protocol is
invoked and an IPSec SA is established and the packet is encrypted and transmitted. If a
match is not found, the packet is transmitted without encryption.
This table can also be used to enable Dead Peer Detection (RFC 3706), whereby the
device queries the liveliness of its IKE peer at regular intervals or on-demand. When two
peers communicate with IKE and IPSec, the situation may arise in which connectivity
between the two goes down unexpectedly. In such cases, there is often no way for IKE and
IPSec to identify the loss of peer connectivity. As such, the Security Associations (SA)
remain active until their lifetimes naturally expire, resulting in a "black hole" situation where
both peers discard all incoming network traffic. This situation may be resolved by
performing periodic message exchanges between the peers. When no reply is received,
the sender assumes SA’s are no longer valid on the remote peer and attempts to
renegotiate.
Notes:
•
Incoming packets whose parameters match one of the entries in the IP
Security Associations table but is received without encryption, is rejected.
•
If you change the device's IP address on-the-fly, you must then reset the
device for IPSec to function properly.
•
The proposal list must be contiguous.
•
For security, once the IKE pre-shared key is configured, it is not
displayed in any of the device's management tools.
•
You can also configure the IP Security Associations table using the table
ini file parameter IPsecSATable (see 'Security Parameters' on page
Содержание Mediant 3000
Страница 1: ...User s Manual Version 6 6 Enterprise Session Border Controller VoIP Digital Media Gateway Mediant 3000...
Страница 2: ......
Страница 21: ...Version 6 6 21 Mediant 3000 User s Manual 1 Overview Figure 1 2 Mediant 3000 TP 6310 Functional Block Diagram...
Страница 22: ...User s Manual 22 Document LTRT 89729 Mediant 3000 Figure 1 3 Mediant 3000 TP 8410 Functional Block Diagram...
Страница 26: ...User s Manual 26 Document LTRT 89729 Mediant 3000 Reader s Note...
Страница 27: ...Part I Getting Started with Initial Connectivity...
Страница 28: ......
Страница 40: ...User s Manual 40 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 41: ...Part II Management Tools...
Страница 42: ......
Страница 44: ...User s Manual 44 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 80: ...User s Manual 80 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 98: ...User s Manual 98 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 103: ...Part III General System Settings...
Страница 104: ......
Страница 113: ...Part IV General VoIP Configuration...
Страница 114: ......
Страница 144: ...User s Manual 144 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 164: ...User s Manual 164 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 222: ...User s Manual 222 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 224: ...User s Manual 224 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 275: ...Part V Gateway and IP to IP Application...
Страница 276: ......
Страница 278: ...User s Manual 278 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 399: ...Part VI Session Border Controller Application...
Страница 400: ......
Страница 402: ...User s Manual 402 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 464: ...User s Manual 464 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 465: ...Part VII Stand Alone Survivability Application...
Страница 466: ......
Страница 474: ...User s Manual 474 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 494: ...User s Manual 494 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 497: ...Part VIII IP Media Capabilities...
Страница 498: ......
Страница 501: ...Part IX High Availability System...
Страница 502: ......
Страница 515: ...Part X Maintenance...
Страница 516: ......
Страница 522: ...User s Manual 522 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 524: ...User s Manual 524 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 552: ...User s Manual 552 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 562: ...User s Manual 562 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 565: ...Part XI Status Performance Monitoring and Reporting...
Страница 566: ......
Страница 578: ...User s Manual 578 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 609: ...Part XII Diagnostics...
Страница 610: ......
Страница 624: ...User s Manual 624 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 626: ...User s Manual 626 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 638: ...User s Manual 638 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 639: ...Part XIII Appendix...
Страница 640: ......
Страница 864: ...User s Manual 864 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 871: ...Version 6 6 871 Mediant 3000 User s Manual 55 Selected Technical Specifications Reader s Notes...
Страница 872: ...User s Manual Ver 6 6 www audiocodes com...