
Issue 5 June 2008
711
Assumptions concerning user behavior
●
Password length:
- User password: at least eight characters
- Other passwords: at least six characters
- PSK (Pre-shared keys) for IKE: at least 13 characters
!
SECURITY ALERT:
SECURITY ALERT:
The user should refer to
Password guidelines
on page 720.
●
Lock-out after authentication fail after fixed number of log-in attempts (default value is
three)
●
Device managed locally via direct link to Console port, and remotely via IPSec tunnel only
●
Commands are documented in the
Avaya G250 and Avaya G350 CLI Reference
,
03-300437
Critical security parameters and private keys
Table 171
describes the CSPs (Critical Security Parameters) defined in the module.
Table 171: Critical security parameters
Key
Description/Usage
IKE Pre-shared Keys
This key generates IKE SKEYID_d during pre-sharedkey
authentication. The first-time key must be entered manually
(via RS232 connected to the PC acting as terminal
emulation). Other keys can be defined remotely over
encrypted and authenticated IPSEC tunnel.
HASH_I, HASH_R
Used for generation of SKEYID, SKEYID_d, SKEYID_a,
SKEYID_e. Generated for VPN IKE phase-1 key
establishment.
IKE Pre-Shared Session Key
(SKEYID)
Generated for VPN IKE phase-1 by hashing pre-shared keys
with responder/receiver nonce
IKE Ephemeral DH shared
secret (g^ab)
Generated for VPN IKE phase-1 key establishment
IKE Ephemeral DH private key
(a)
The private exponent used in DH exchange. Generated for
VPN IKE phase-1 key establishment.
1 of 3
Содержание Media Gateway G250
Страница 1: ...Administration for the Avaya G250 and Avaya G350 Media Gateways 03 300436 Issue 5 June 2008 ...
Страница 24: ...Contents 24 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 32: ...Introduction 32 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 38: ...Configuration overview 38 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 128: ...Basic device configuration 128 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 210: ...Configuring Standard Local Survivability SLS 210 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 244: ...Configuring logging 244 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 258: ...Configuring VoIP QoS 258 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 354: ...Configuring Emergency Transfer Relay ETR 354 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 370: ...Configuring SNMP 370 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 402: ...Configuring advanced switching 402 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 486: ...Configuring monitoring applications 486 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 548: ...Configuring the router 548 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 664: ...Configuring policy 664 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 682: ...Configuring policy based routing 682 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 686: ...Setting synchronization 686 Administration for the Avaya G250 and Avaya G350 Media Gateways ...