![Comnet reliance RL1000GW Скачать руководство пользователя страница 147](http://html1.mh-extra.com/html/comnet/reliance-rl1000gw/reliance-rl1000gw_installation-and-operation-manual_2644386147.webp)
INS_RL1000GW_REV– 15 Jul 2016 PAGE 147
INSTALLATION AND OPERATION MANUAL
RL1000GW
TECH SUPPORT: 1.888.678.9427
ISAKMP Phase 2
At this phase the negotiation of SA to secure the VPN GRE data using IPSec is made.
Modes
The common mode to use between end stations supporting IPSec (the VPN parties) is called
Transport mode. This is the mode supported by ComNet.
Perfect forward secrecy (PFS)
The PFS is a part of the key agreement session and has a purpose to ensure that a session
key derived from a set of long-term public and private keys will not be compromised if one of
the (long-term) private keys is compromised in the future. The VPN (GRE, IPSEC) sessions can
negotiate new keys for every communication and if a key is compromised only the specific session
it protected will be revealed.
The PFS uses as well the D-H groups but independently from phase 1.
Settings structure
»
Supported mode
›
Transport (yes)
›
Tunnel (no)
»
Authentication s HASH algorithms
›
Secure Hash Algorithm SHA-1 (160 bit)
›
Secure Hash Algorithm SHA-2 (256 |512 bit)
›
Message Digest (MD5) (128 bit)
»
Perfect Forward Secrecy type (PFS)
»
Encryption algorithm
›
Advanced Encryption Standard (AES)
∙
128 and 256 key size options
∙
symmetric algorithm
›
Triple Data Encryption Algorithm (3DES)
∙
comprises of three DES keys, K1, K2 and K3, each of 56 bits
»
Life time
›
Soft – hard coded. At this threshold value the IKE starts a new phase 2 exchange.
›
Hard- SA which has exceeded this threshold value will be discarded.