
iSG4F
User’s Manual
iS5 Communications Inc.
131
IPSec negotiation (Quick Mode) begins.
In applications at which the IP addresses used for the VPN network are not static (for example
a cellular spoke retrieving dynamic IP from the ISP over its PPP interface) the Main mode of
IKE is not applicable.
Pre-shared key
When used in main mode the PSK must be in the form of IP address and use the VPN network
addresses of the parties.
NOTE
In Applications where the VPN is used over a cellular link, the IKE mode to be
used is Aggressive. Main mode is not applicable.
Aggressive
In this mode the negotiation is quicker as the session is completed in only 3 messages. The
disadvantage is in that the identity of the peers is not protected.
The first two messages negotiate policy, exchange Diffie-Hellman public values and ancillary
data necessary for the exchange, and identities. In addition the second message
authenticates the responder. The third message authenticates the initiator and provides a
proof of participation in the exchange.
The initiator sends a request with all required SA information.
The responder replies with authentication and its ID.
The initiator authenticates the session in the follow-up message.
Pre-shared key
When used in Aggressive mode the PSK may be either in the form of IP address or fqdn. The
PSK doesn’t have to be the actual IP addresses of the VPN network interfaces as it considers
the enter value as text (in the format of IP) and not as a valid IP address.
NOTE
In Applications where the VPN is used over a cellular link, the IKE mode to be
used is Aggressive. The PSK may be of IP format or fqdn
Settings structure