42
VoIP Subscriber Gateways
you to organize the following 4 network topologies with using encryption traffic via
IPSec protocol: point-to-point, network-to-point, point-to-network, network-to-
network;
-
Remote gateway
– gateway used for remote network access;
-
Security protocol
– there are two key protocols: AH (Authentication header) and EPS
(Encapsulating Security Payload). The first provides data authentication except data
encryption; the second provides both operations. The device supports only the ESP
protocol. IPSec can operate in one of the two modes: ‘transport’ or ‘tunnel’. In the first
case, contents of IP-packet (payload) is encrypted and/or authenticated except the
header. In the second case, contents of initial IP-packet is encrypted and/or
authenticated totally and new header is added to it. TAU-8.IP device operates only in
the tunnel mode;
-
Manual key exchange method
– when manual mode is set, authentication and
encryption keys are specified manually. This mode is not recommended to use. The
following settings are available when the mode is disabled:
NAT-Traversal IPSec - NAT-T mode selection. NAT-T (NAT Traversal) encapsulates
IPSec traffic and simultaneously creates UDP packets to be sent correctly by a NAT
device. For this purpose, NAT-T adds an additional UDP header before IPSec packet
so it would be processed as an ordinary UDP packet and the recipient host would
not perform any integrity checks. When the packet arrives to the destination, UDP
header is removed and the packet goes further as an encapsulated IPSec packet.
With NAT-T technique, you may establish communication between IPSec clients in
secured networks and public IPSec hosts via firewalls. You can choose one of the
three NAT-T operation modes:
on – NAT-T mode is activated only when NAT is detected on the way to the
destination host;
force – use NAT-T in any case;
off – disable NAT-T on connection establishment.
The following NAT-T settings are available:
UDP port NAT-T – UDP port for packets used for IPSec message encapsulation.
Default value is 4500;
NAT-T keepalive packet transmission interval, sec – periodic message transmission
interval for UDP connection keepalive on the device performing NAT functions.
Aggressive mode – phase 1 operation mode, when all the necessary data is
exchanged using three unencrypted packets. In the main mode, the exchange
process involves six unencrypted packets.