Configuration
4.10 IPsec Tunnel Configuration
Continued from previous page
Item
Description
IKE Reauthentication
Enable or disable IKE reauthentication (IKEv2 only).
XAUTH Enabled
Enable extended authentication (for IKEv1 only).
XAUTH Mode
Select XAUTH mode (client or server).
XAUTH Username
XAUTH username.
XAUTH Password
XAUTH password.
ESP Algorithm
Specifies the means by which the router selects the algorithm:
•
auto
– The encryption and hash algorithm are selected au-
tomatically.
•
manual
– The encryption and hash algorithm are defined
by the user.
ESP Encryption
Encryption algorithm – DES, 3DES, AES128, AES192, AES256,
AES128GCM128, AES192GCM128, AES256GCM128.
ESP Hash
Hash algorithm – MD5, SHA1, SHA256 or SHA512.
PFS
Enables/disables the Perfect Forward Secrecy function. The
function ensures that derived session keys are not compromised
if one of the private keys is compromised in the future.
PFS DH Group
Specifies the Diffie-Hellman group number (see
IKE DH Group
).
Key Lifetime
Lifetime key data part of tunnel. The minimum value of this pa-
rameter is 60 s. The maximum value is 86400 s.
IKE Lifetime
Lifetime key service part of tunnel. The minimum value of this
parameter is 60 s. The maximum value is 86400 s.
Rekey Margin
Specifies how long before a connection expires that the router
attempts to negotiate a replacement. Specify a maximum value
that is less than half of IKE and Key Lifetime parameters.
Rekey Fuzz
Percentage of time for the Rekey Margin extension.
DPD Delay
Time after which the IPsec tunnel functionality is tested.
DPD Timeout
The period during which device waits for a response.
Authenticate Mode
Specifies the means by which the router authenticates:
•
Pre-shared key
– Sets the shared key for both sides of the
tunnel.
•
X.509 Certificate
– Allows X.509 authentication in multi-
client mode.
Pre-shared Key
Specifies the shared key for both sides of the tunnel. The prereq-
uisite for entering a key is that you select pre-shared key as the
authentication mode.
CA Certificate
Certificate for X.509 authentication.
Remote Certificate
\
PubKey
Certificate for X.509 authentication or PubKey for public key sig-
nature authentication.
Continued on next page
UM Configuration OWL LTE M12
Rel. 06.1.09 - 07/2019
77