Siemens 5890 manual IKE IPSec Proposals Definition

Page 90

SIEMENS 5890 DSL Router

Chapter 6 Security Setup

User’s Guide

IKE/IPSec Configuration

 

 

IKE IPSec Proposals Definition

IKE IPSec Proposals specify how packets will be encrypted/authenticated for the final SA. IPSec uses SAs (Security Associations) for making connections between two devices. An SA is an instance of a security policy and keying material applied to a data flow. SAs are negotiated between the two connection endpoints and contain information on sequence numbering.

An IPSec SA is unidirectional, applying to only one direction of data flow, so a set of SAs is needed for a secure connection. For each security protocol used, one SA is needed for each direction (inbound and outbound).

An IPSec connection uses a security protocol (AH or ESP) that authenticates the sender of each data packet. Usually, only one security protocol is used for a connection, so the connection would use two SAs (one inbound and one outbound). However, it is possible for the same connection to be configured to use both the ESP and the AH protocol. In this case, four SAs would be required (one inbound and one outbound for the AH protocol, and one inbound and one outbound for the ESP protocol.

To define a new IKE IPSec proposal:

1.Click Create next to IKE IPSec Proposals from the Advanced IKE/IPSec Setup page. This displays the IKE IPSec Proposal Definition page.

2.In IPSec Proposal Name, enter the logical name for the IKE IPSec Proposal Definition. This name is of no importance to the remote IKE peer.

SIEMENS

84

Image 90
Contents 5890 Software License and Limited Warranty Software LicenseGeneral Provisions Table of Contents User Setup Advanced SetupSecurity Setup Monitoring Router Front Panel Back PanelHardware Specifications Software Specifications Frame Relay PPP RFC 1661, RFCSecurity Installation Requirements Package ContentsPC Requirements Network Service Provider Requirements Hardware Installation PC Configuration Windows 98/MEWindows NT Select TCP/IP Protocol from the Network Protocols listWindows Windows XP Mac OS Mac OSX Linux Configuring the Router Establish ConnectionRouter Information To do this Refer toAccess Easy Setup Wizard Select ProtocolBridging Enabled IP Routing EnabledPoint-to-Point Protocol over ATM VC Multiplexing NAT Enabled Block Net Bios TrafficPoint-to-Point Protocol over ATM LLC Encapsulation NAT Enabled RFC 1483 Multiprotocol Encapsulation LLC/SNAP RFC 1483 VC Multiplexing Routed Point-to-Point Protocol over Ethernet over RFC1483 RFC 1483 MAC Encapsulated Routing MER RAW IP Dynamic Host Configuration Protocol Local Area Network Configuration User Setup User ManagementAdding/Modifying a User Account Deleting a User Account Radius User LookupLocal NoneSecure Mode Configuration TrustedUntrusted Configure the Radius Server Configure the TacPlus Server Management Classes Class Functional AreasChange Password Click Save and Reboot Access ControlNo access restrictions Telnet WebAdvanced Setup WAN Selection Sdsl ATM or Sdsl Frame RelayRemote File Configuration DMZ DMZ Router Clock Dhcp Dhcp Differentiated Services Framework Weighted Fair QueuingQoS Configure QoS policies Configure QoS Policy Siemens Reorder QoS Policies To the endBefore policy Routing Table Configuration Dial Backup Click Enable Dial BackupATM Traffic Shaping Non Real-Time Variable Bit Rate Constant Bit RateReal-Time Variable Bit Rate Unspecified Bit RateSwitch Management Switch Mirror Configuration Switch Age Time Command Line Interface File Editor Security Setup NAT NAT Server Configuration NAT Host Mapping Disable DefaultPort Number Snmp IP Filter Click Add IP RangeSnmp Password Enter the New Password and New Password againSecure Shell Key GeneratorConfigure SSH Load Keys Key Generator Firewall Scripts Stateful Firewall Firewall RulesConfigure Stateful Firewall View Dropped Packets Configure Firewall Rules Protocol/Port ApplicationDelete Firewall Rules IKE/IPSec Configuration Easy IKE/IPSec Setup Advanced IKE/IPSec Setup IKE PeersIKE Peers Definition IKE Proposals Definition IKE IPSec Proposals Definition Siemens IKE IPSec Policies Definition Siemens VPN Log On Monitoring Router System SummaryEthernet Interface Information Remote Connection InformationIP Routing Information System InformationDiagnostics PPPoE SessionInterface Information ATM StatisticsRouting Table Information Files InformationList All Configuration Data Memory UsageTCP/IP Statistics