
Prestige 652 Series User’s Guide
VPN Screens
17-13
17.10 IKE Phases
There are two phases to every IKE (Internet Key Exchange) negotiation – phase 1 (Authentication) and phase
2 (Key Exchange). A phase 1 exchange establishes an IKE SA and the second one uses that SA to negotiate
SAs for IPSec.
Figure 17-4 Two Phases to Set Up the IPSec SA
In phase 1 you must:
Choose a negotiation mode.
Authenticate the connection by entering a pre-shared key.
Choose an encryption algorithm.
Choose an authentication algorithm.
Choose a Diffie-Hellman public-key cryptography key group (
DH1
or
DH2
)
.
Set the IKE SA lifetime. This field allows you to determine how long an IKE SA should stay up
before it times out. An IKE SA times out when the IKE SA lifetime period expires. If an IKE
SA times out when an IPSec SA is already established, the IPSec SA stays connected.
In phase 2 you must:
Choose which protocol to use (
ESP
or
AH
) for the IKE key exchange.
Choose an encryption algorithm.
Choose an authentication algorithm
Choose whether to enable Perfect Forward Secrecy (PFS) using Diffie-Hellman public-key
cryptography – see
section 17.10.3
. Select
None
(the default) to disable PFS.
Choose
Tunnel
mode or
Transport
mode.
Set the IPSec SA lifetime. This field allows you to determine how long the IPSec SA should
stay up before it times out. The Prestige automatically renegotiates the IPSec SA if there is
traffic when the IPSec SA lifetime period expires. The Prestige also automatically renegotiates
the IPSec SA if both IPSec routers have keep alive enabled, even if there is no traffic. If an
IPSec SA times out, then the IPSec router must renegotiate the SA the next time someone
attempts to send traffic.
Содержание Prestige 652
Страница 1: ...Prestige 652 Series ADSL Security Wireless LAN Router User s Guide Version 3 40 August 2003...
Страница 48: ...Prestige 652 Series User s Guide 1 10 Getting To Know Your Prestige Figure 1 4 Prestige LAN to LAN Application...
Страница 92: ......
Страница 104: ...Prestige 652 Series User s Guide 7 12 WAN Setup Figure 7 6 Advanced WAN Backup...
Страница 112: ......
Страница 133: ......
Страница 147: ......
Страница 178: ...VPN IPSec V Part V VPN IPSec This part provides information about configuring VPN IPSec for secure communications...
Страница 192: ...Prestige 652 Series User s Guide 17 8 VPN Screens Figure 17 3 VPN IKE...
Страница 232: ......
Страница 252: ...Maintenance VIII Part VIII Maintenance This part covers the maintenance screens...
Страница 254: ...Prestige 652 Series User s Guide 22 2 Maintenance Figure 22 1 System Status...
Страница 268: ......
Страница 278: ......
Страница 294: ......
Страница 310: ......
Страница 352: ......
Страница 414: ......
Страница 418: ......
Страница 428: ......
Страница 433: ...XII Part XII Appendices and Index This part contains additional background information and an index or key terms...
Страница 434: ......
Страница 440: ......
Страница 451: ...Prestige 652 Series User s Guide Wireless LAN and IEEE 802 11 C 3 Diagram C 2 ESS Provides Campus Wide Coverage...
Страница 452: ......
Страница 456: ......
Страница 496: ......
Страница 510: ......