Number {180 – 86400}, default = 14400 s (4 hours)
Time of SA validity. The new key exchange or re-authentication is triggered immediately the
key expires. The true time of expiration is randomly selected within the range of 90-110%, to
prevent collision when the key exchange is triggered from both sides simultaneously.
Unfortunately, the more frequent the key exchange, the higher the network and CPU load.
•
Phase 2 – IPsec
Certain parameters are shared by all subordinate CHILD SA. IPsec Security Association provides
packet encryption (user traffic encryption).
○
Encryption algorithm
List box {3DES (legacy); AES128; AES192; AES256}, default = "AES128"
IKE CHILD SA encryption algorithm. The "legacy" marked methods are recognized as unsafe.
Peer configuration must match.
○
Authentication algorithm
List box {MD5 (legacy); SHA1 (legacy); SHA256; SHA384; SHA512}, default = "SHA256"
IKE CHILD SA integrity algorithm. The "legacy" marked methods are recognized as unsafe.
Peer configuration must match.
The same value as selected for the Integrity algorithm, is used for the PRF (Pseudo-Random
Function).
○
Diffie-Hellman group (PFS)
List box {None (legacy); Group 2 (MODP1024, legacy); Group 5 (MODP1536, legacy);
Group 14 (MODP2048); Group 15 (MODP3072); Group 25 (ECP192); Group 26 (ECP224),
Group 19 (ECP256); Group 20 (ECP384); Group 21 (ECP521); Group 27 (ECP224BP);
Group 28 (ECP256BP); Group 29 (ECP384BP); Group 30 (ECP512BP)}, default = "Group 15
(MODP3072)"
The PFS (Perfect Forward Secrecy) feature is performed using the Diffie-Hellman group
method.
PFS increases IKE CHILD SA key exchange security. The RipEX2 unit load is seriously affected
when key exchange is in process. The "legacy" marked methods are recognized as unsafe.
Peer configuration must match.
The higher the Diffie-Hellman group, the higher the security but also the higher the network
and CPU load.
○
Payload compression
List box {On; Off}, default = "Off"
This parameter enables payload compression. This takes place before encryption. Peer con-
figuration must match
○
SA lifetime [s]
Number {180 – 86400}, default = 3600 s (1 hour)
Time of CHILD SA validity. The new key exchange or re-authentication is triggered immediately
the key expires. The true time of expiration is randomly selected within the range of 90-110%,
to prevent collision when the key exchange is triggered from both sides simultaneously.
The SA lifetime for CHILD SA is normally much shorter than SA lifetime for IKE SA because
the CHILD SA normally transfers much more data than IKE SA (key exchange only). Changing
the keys serves as protection against breaking the cypher by analyzing big amounts of data
encrypted by the same cypher.
•
PSK
PSK (Pre-shared key) authentication is used for IKE SA authentication. The relevant peer is
identified using it's "Peer ID". The key must be the same for both local and peer side of the IPsec.
RipEX2 Radio modem & Router – © RACOM s.r.o.
136
Settings
Содержание RipEX2
Страница 2: ......
Страница 12: ...Fig 1 2 RipEX2 bench testing RipEX2 Radio modem Router RACOM s r o 12 Quick guide...
Страница 14: ...2 1 Dimensions Fig 2 1 RipEX2 dimensions RipEX2 Radio modem Router RACOM s r o 14 Product...
Страница 138: ...RipEX2 Radio modem Router RACOM s r o 138 Settings...
Страница 225: ...Fig 10 1 Sample document 1 3 225 RACOM s r o RipEX2 Radio modem Router Safety regulations warranty...
Страница 226: ...Fig 10 2 Sample document 2 3 RipEX2 Radio modem Router RACOM s r o 226 Safety regulations warranty...
Страница 227: ...Fig 10 3 Sample document 3 3 227 RACOM s r o RipEX2 Radio modem Router Safety regulations warranty...
Страница 234: ...Fig 10 7 Grant for RipEX2 1A RipEX2 Radio modem Router RACOM s r o 234 Safety regulations warranty...
Страница 235: ...Fig 10 8 TCB Grant for RipEX2 4A 235 RACOM s r o RipEX2 Radio modem Router Safety regulations warranty...
Страница 236: ...Fig 10 9 TCB authorization RipEX2 Radio modem Router RACOM s r o 236 Safety regulations warranty...
Страница 237: ...Fig 10 10 FCB certificate for RipEX2 1A 237 RACOM s r o RipEX2 Radio modem Router Safety regulations warranty...