SIP User's Manual
202
Document #: LTRT-65409
MediaPack
Series
Table
5-41: IPSec SPD Table Configuration Parameters
Parameter Name
Description
Remote IP Address
[IPSecPolicyRemoteIPAdd
ress]
Defines the destination IP address (or a FQDN)
the IPSec mechanism is applied to.
This parameter is mandatory.
Note:
When an FQDN is used, a DNS server must
be configured (DNSPriServerIP).
Local IP Address Type
[IPSecPolicyLocalIPAddre
ssType]
Determines the local interface to which the
encryption is applied (applicable to multiple IPs
and VLANs).
[0]
OAM = OAM interface (default).
[1]
Control = Control interface.
Source Port
[IPSecPolicySrcPort]
Defines the source port the IPSec mechanism is
applied to.
The default value is 0 (any port).
Destination Port
[IPSecPolicyDstPort]
Defines the destination port the IPSec mechanism
is applied to.
The default value is 0 (any port).
Protocol
[IPSecPolicyProtocol]
Defines the protocol type the IPSec mechanism is
applied to.
0 = Any protocol (default).
17 = UDP.
6 = TCP.
Any other protocol type defined by IANA
(Internet Assigned Numbers Authority).
IPSec is applied to
outgoing packets
whose IP address,
destination port,
source port and
protocol type match
the values defined
for these four
parameters.
Related Key Exchange
Method Index
[IPsecPolicyKeyExchange
MethodIndex]
Determines the index for the corresponding IKE entry. Note that several
policies can be associated with a single IKE entry.
The valid range is 0 to 19. The default value is 0.
IKE Second Phase Parameters (Quick Mode)
SA Lifetime (sec)
[PsecPolicyLifeInSec]
Determines the time (in seconds) the SA negotiated in the second IKE
session (quick mode) is valid. After the time expires, the SA is re-
negotiated.
The default value is 28800 (8 hours).
SA Lifetime (KB)
[IPSecPolicyLifeInKB]
Determines the lifetime (in kilobytes) the SA negotiated in the second
IKE session (quick mode) is valid. After this size is reached, the SA is
re-negotiated.
The default value is 0 (this parameter is ignored).
The lifetime parameters (IPsecPolicyLifeInSec and IPSecPolicyLifeInKB) determine the duration of
which an SA is valid. When the lifetime of the SA expires, it is automatically renewed by performing
the IKE second phase negotiations. To refrain from a situation where the SA expires, a new SA is
being negotiated while the old one is still valid. As soon as the new SA is created, it replaces the old
one. This procedure occurs whenever an SA is about to expire.
Содержание Mediapack mp-11x
Страница 1: ...Document LTRT 65409 August 2007 User s Manual Version 5 2...
Страница 2: ......
Страница 14: ...SIP User s Manual 14 Document LTRT 65409 MediaPack Series Reader s Notes...
Страница 18: ...SIP User s Manual 18 Document LTRT 65409 MediaPack Series Reader s Notes...
Страница 22: ...SIP User s Manual 22 Document LTRT 65409 MediaPack Series Reader s Notes...
Страница 44: ...SIP User s Manual 44 Document LTRT 65409 MediaPack Series Reader s Notes...
Страница 47: ...Version 5 2 47 August 2007 SIP User s Manual 4 Getting Started Figure 4 1 Startup Process...
Страница 322: ...SIP User s Manual 322 Document LTRT 65409 MediaPack Series Reader s Notes...
Страница 380: ...SIP User s Manual 380 Document LTRT 65409 MediaPack Series Reader s Notes...
Страница 388: ...SIP User s Manual 388 Document LTRT 65409 MediaPack Series Reader s Notes...
Страница 390: ...User s Manual Version 5 2 www audiocodes com...