6-14 Administrator’s Handbook
•
The
ESP Encryption Transform
pop-up menu (which is visible only if you have selected ESP or AH+ESP
encapsulation) allows you to specify the type of ESP encr yption: DES, 3DES, or NULL (no encr yption).
•
The
ESP Authentication Transform
pop-up menu (which is visible only if you have selected ESP or AH+ESP
encapsulation) allows you to specify the type of ESP authentication: None, HMAC-MD5-96, or
HMAC-SHA1–96.
Advanced IPsec Options
If you select
Advanced IPsec Options
, the Advanced IPsec Options screen appears.
This screen allows you to specify the lifetime associated with each IPsec Security Association (SA) and control
when the SA will expire and become invalid.
•
SA Lifetime (seconds)
specifies the duration in seconds for which the SA will remain valid. The range of
permissible values is the set of non-negative integer values between 0 and 2^32-1. The default value is
28,800 seconds (1 hour). The value zero specifies the absence of an elapsed time lifetime.
•
SA Lifetime (Kilobytes)
specifies the maximum number of kilobytes of data that may be secured
(encr ypted/decr ypted or authenticated) using the SA before it expires and becomes invalid. The range of
permissible values is the set of non-negative integer values between 0 and 2^32-1. The default value is 0
Kilobytes. The value zero specifies the absence of a secured data lifetime.
Note:
It is invalid to set both lifetime values to zero! This condition is not enforced by the console (in order to
avoid order dependencies when configuring the items), but rather is enforced at runtime and will cause the
IPsec profile to assume the defaults. In such a case, the SA Lifetime (seconds) will default to 300 seconds.
•
Perfect Forward Secrecy
toggles whether or not Per fect For ward Secrecy will be used. Enabling Per fect
For ward Secrecy (the default) causes IKE to per form a new Diffie-Hellman exchange with each Phase 2
Advanced IPsec Options
SA Lifetime seconds: 28800
SA Lifetime Kbytes: 0
Perfect Forward Secrecy: Yes
Dead Peer Detection: No
Содержание Netopia Embedded Software
Страница 1: ...Administrator s Handbook Motorola Netopia Embedded Seftware Version 8 7 4 Enterprise Series Routers ...
Страница 10: ...x Administrator s Handbook ...
Страница 16: ...1 6 Administrator s Handbook ...
Страница 44: ...2 28 Administrator s Handbook ...
Страница 108: ...3 64 Administrator s Handbook ...
Страница 176: ...5 34 Administrator s Handbook ...
Страница 202: ...6 26 Administrator s Handbook ...
Страница 243: ...IP Setup 7 41 Additional LAN Configuration Name IP Address Additional LAN 1 1 1 1 1 Additional LAN 2 0 0 0 0 ...
Страница 244: ...7 42 Administrator s Handbook ...
Страница 340: ...Index 6 ...