The protocol used for secure key exchange is IKE (Internet Key Exchange). Both IKE version 1 and
the newer version 2 are available in M!DGE3.
IKE protocol communication with the peer is established using UDP frames on port 500. However, if
NAT-T (NAT Traversal) or MOBIKE (MOBile IKE) are active, the UDP port 4500 is used instead.
Note
NAT-T is automatically recognized by IPsec implementation in M!DGE3.
The IPsec tunnel is provided by Security Association (SA). There are 2 types of SA:
• IKE SA: IKE Security Association providing SA keys exchange with the peer.
• CHILD SA: IPsec Security Association providing packet encryption.
Every IPsec tunnel contains 1 IKE SA and at least 1 CHILD SA.
Link partner (peer) secure authentication is assured using Pre-Shared Key (PSK) authentication
method: Both link partners share the same key (password).
As and when the CHILD SA expires, new keys are generated and exchanged using IKE SA.
As and when the IKE SA version IKEv1 expires - new authentication and key exchange occurs and a
new IKE SA is created. Any CHILD SA belonging to this IKE SA is re-created as well.
As and when the IKE SA version IKEv2 expires one of two different scenarios might occur:
• If the re-authentication is required - the behavior is similar to IKEv1 (see above).
• It the re-authentication is not required - only new IKE SA keys are generated and exchanged.
IPsec
{Enable; Disable}, default = "Disable"
IPsec system turning On/Off
M!DGE3 Cellular Router – © RACOM s.r.o.
110
Settings
Содержание M!DGE3
Страница 2: ......
Страница 11: ...2 1 Dimensions Fig 2 1 M DGE3 dimensions 11 RACOM s r o M DGE3 Cellular Router Product...
Страница 116: ...M DGE3 Cellular Router RACOM s r o 116 Settings...
Страница 134: ...Tab 7 3 Configuration versions FW version CNF version 2 0 13 0 1 M DGE3 Cellular Router RACOM s r o 134 Settings...