The SA lifetime for CHILD SA is normally much shorter than SA lifetime for IKE SA because the
CHILD SA normally transfers much more data than IKE SA (key exchange only). Changing the
keys serves as protection against breaking the cypher by analyzing big amounts of data encrypted
by the same cypher.
Unfortunately, the more frequent the key exchange, the higher the network and CPU load.
Pre-shared keys
PSK (Pre-shared key) authentication is used for IKE SA authentication. The relevant peer is
identified using it's "Peer ID". The key must be the same for both local and peer side of the IPsec
tunnel.
Mode
List box: Pass phrase, Key
Default = Pass phrase
How the PSK key is entered.
Pass phrase
The PSK key is entered as a password. Empty password is not allowed.
Key
The 256 bits long PSK key is entered as a hexadecimal number containing 64 digits.
Generate
The Generate button creates a new 256 bits long PSK key and enters it in the
Key
field.
■
IPsec diagnostics
Refresh status
The IKE SA status is indicated by the color assigned to the configuration row in the IPsec asso-
ciations table after the "Refresh status" button is selected:
•
Green color; "Up" status; The IKE SA is established. The associated CHILD SA are also
established under normal conditions.
•
Red color; "Down" status; The IKE SA is not established.
•
Gray color; "Unknown" status; The IKE SA status is not available. The individual CHILD SA
line can be gray if:
it is not marked as Active, or
its configuration was not accepted
Monitoring
•
IPsec uses UDP frames with port 500 or 4500. IP protocol number 50 is ESP (Encapsulating
Security Payloads).
•
When using monitoring filters, the "Protocol type" filter "UDP and "Other" can be used.
•
Example of ESP packet monitoring:
14:26:21.899413 [RF:phy:Rx] IP 10.10.1.67 > 10.10.1.41: IP protocol 50, length ►
174, rss:53 dq:223
RLhead:
4880 ffab 8f5a 5a40 ((MC:B0) 10.10.1.67 > 10.10.1.41 DATA_RTS: T:255 ►
LN:90 Rp:- nA:y Ofr:0)
DChead:
04 (|F:-|C:-|E:a|)
171
© RACOM s.r.o. – RipEX Radio modem & Router
Advanced Configuration
Содержание RipEX
Страница 2: ......
Страница 42: ... DQ Data Quality Min 180 PER Packet Error Rate Max 5 RipEX Radio modem Router RACOM s r o 42 Network planning ...
Страница 222: ...Fig 10 3 ATEX Certificate RipEX 2 3 RipEX Radio modem Router RACOM s r o 222 Safety environment licensing ...
Страница 223: ...Fig 10 4 ATEX Certificate RipEX 3 3 223 RACOM s r o RipEX Radio modem Router Safety environment licensing ...