Configuration - Page 29
IPSec Policies tab
The IPSec Policies tab is used to configure and complete the SA policy. Each SA
requires a unique IPSec form for each peer, which can be either a client or another
IPSec Gateway (see page 27).
Figure 12. The IPSec Policies tab
Caution:
Although the IPSec Menu is displayed and can be completed, a valid IPSec
Tunneling licence is required for the feature to be activated (see The IP
Security Menu on page 24).
Parameter Options
Description
Protocol
ESP (Encapsulation Security
Payload)
AH (Authentication Header)
ESP
Provides authentication, integrity and
confidentiality. Secures everything in the
packet that follows the header. Also
authenticates the packet payload on a
packet-by-packet basis.
AH.
No encryption, encapsulation or
confidentiality. Only authentication and
integrity. Also authenticates portions of the
IP header of the packet (source
/destination).
Encryption
DES - 56 Bit
3DES - 168 Bit
AES – 128, 192, 256
The encryption method to be used.
3DES requires an IP Office Licence.
Authentication HMAC MD5 – 128 bit.
HMAC SHA – 160 bit.
The method of password authentication.
Life Time
<Seconds or Kilobytes >
Set whether
Life
below is measured in
seconds or Kilobytes.
Life
Blank at default – set in either
seconds or Kilobytes as
defined in
Life Time
above
Determines the period of time or the
number bytes after which the SA key is
refreshed or re-calculated.
IP Office (R3.0) Virtual Private Networking
Configuration - Page 29
40DHB0002UKER Issue 3 (4th February 2005)
IPSec Configuration