Robustel R3010 User Guide
RT_UG_R3010_v.1.0.2 8 Aug., 2018 59
Confidential
IKE Settings
Item
Description
Default
Authentication
Algorithm
Select from “MD5”, “SHA1”, “SHA2 256” or “SHA2 512” to be used in IKE
negotiation.
MD5
Encryption Algorithm Select from “3DES”, “AES128” and “AES256”to be used in IKE negotiation.
3DES: Use 168-bit 3DES encryption algorithm in CBC mode
AES128: Use 128-bit AES encryption algorithm in CBC mode
AES256: Use 256-bit AES encryption algorithm in CBC mode
3DES
IKE DH Group
Select from “DHgroup2”, “DHgroup5”, “DHgroup14”, “DHgroup15”,
“DHgroup16”, “DHgroup17” or “DHgroup18” to be used in key negotiation
phase 1.
DHgroup2
Authentication Type
Select from “PSK”, “CA”, “xAuth PSK” and “xAuth CA” to be used in IKE
negotiation.
PSK: Pre-shared Key
CA: Certification Authority
xAuth: Extended Authentication to AAA server
PSK
PSK Secret
Enter the pre-shared key.
Null
Local ID Type
Select from “Default”, “FQDN” and “User FQDN” for IKE negotiation.
Default: Uses an IP address as the ID in IKE negotiation
FQDN: Uses an FQDN type as the ID in IKE negotiation. If this option is
selected, type a name without any at sign (@) for the local security
gateway, e.g., test.robustel.com.
User FQDN: Uses a user FQDN type as the ID in IKE negotiation. If this
option is selected, type a name string with a sign “@” for the local
security gateway, e.g., [email protected].
Default
Remote ID Type
Select from “Default”, “FQDN” and “User FQDN” for IKE negotiation.
Default: Uses an IP address as the ID in IKE negotiation
FQDN: Uses an FQDN type as the ID in IKE negotiation. If this option is
selected, type a name without any at sign (@) for the local security
gateway, e.g., test.robustel.com.
User FQDN: Uses a user FQDN type as the ID in IKE negotiation. If this
option is selected, type a name string with a sign “@” for the local
security gateway, e.g., [email protected].
Default
Private Key Password Enter the private key under the “CA” and “xAuth CA” authentication types.
Null
Username
Enter the username used for the “xAuth PSK” and “xAuth CA” authentication
types.
Null
Password
Enter the password used for the “xAuth PSK” and “xAuth CA” authentication
types.
Null
IKE Lifetime
Set the lifetime in IKE negotiation. Before an SA expires, IKE negotiates a
new SA. As soon as the new SA is set up, it takes effect immediately and the
old one will be cleared automatically when it expires.
86400