Siemens 5881 manual Siemens

Page 77

SIEMENS 5881 Broadband Internet Router

Chapter 6 Security Setup

User’s Guide

IKE/IPSec Configuration

 

 

5.From the ESP Encryption Scheme drop-down menu, select one of the following to specify the algorithm to use to encrypt ESP IPSec packets:

NONE: No ESP encapsulation and no encryption is used.

NULL: ESP encapsulation, but no data encryption. ESP encapsulation verifies the source, but data is sent in the clear to increase throughput.

DES-CBC: Encrypts using a 56-bit key.

3-DES: Encrypts using three 56-bit keys to produce 168-bit encryption.

AES: Encrypts using a 128-, 192-, or 256-bit key.

6.If you selected AES as the encryption type, specify the key bit size to use in Key Length. This can be 128, 192, or 256.

7.In Phase II Proposal Lifetime, enter the number of seconds after the IPSec SA expires. The default is 1800 seconds. Once this time is elapsed, the system will renegotiate the IKE connection.

8.In Phase II Proposal Life Data, enter the amount of data, measured in kilobytes, before the IPSec SA terminates. After the specified quantity of data has been transferred, the system will renegotiate the IKE connection. If zero is entered, the data quantity will be unlimited. By setting a limit on the amount of data transferred, the risk of a key becoming compromised is reduced.

9.Click Apply.

SIEMENS

71

Image 77
Contents Siemens Business Class Software License Software License and Limited WarrantyGeneral Provisions Table of Contents Security Setup User SetupAdvanced Setup Monitoring Router Front Panel Product SpecificationsConnection Function Back PanelHardware Specifications Software Specifications Security Package Contents Installation RequirementsNetwork Service Provider Requirements PC RequirementsHardware Installation Windows 98/ME PC ConfigurationSelect TCP/IP Protocol from the Network Protocols list Windows NTWindows Windows XP Mac OS Mac OSX Linux Establish Connection Configuring the RouterTo do this Refer to Router InformationSelect Protocol Access Easy Setup WizardNot Using PPPoE Using PPPoEDynamic Host Configuration Protocol Siemens User Management User SetupAdding/Modifying a User Account Deleting a User Account Local User LookupRadius TacplusUntrusted Secure Mode ConfigurationTrusted Configure the Radius Server Configure the TacPlus Server Class Functional Areas Management ClassesChange Password No access restrictions Access ControlClick Save and Reboot Telnet WebAdvanced Setup Apply DMZDMZ Router Clock Dhcp Dhcp QoS Differentiated Services FrameworkWeighted Fair Queuing Configure QoS policies Configure QoS Policy Siemens Before policy Reorder QoS PoliciesTo the end Routing Table Configuration Click Enable Dial Backup Dial BackupSwitch Management Switch Age Time Command Line Interface File Editor Security Setup NAT Configure NATConfigure the NAT Server Configure Host Mapping Port Number DisableDefault Enter the New Password and New Password again Snmp PasswordSnmp IP Filter Click Add IP RangeKey Generator Secure ShellConfigure SSH Load Keys Key Generator Firewall Scripts Firewall Rules Stateful FirewallConfigure Stateful Firewall View Dropped Packets Configure Firewall Rules Application Protocol/PortDelete Firewall Rules IKE/IPSec Configuration Easy IKE/IPSec Setup IKE Peers Advanced IKE/IPSec Setup IKE Peers Definition IKE Proposals Definition IKE IPSec Proposals Definition Siemens IKE IPSec Policies Definition Siemens VPN Log On System Summary Monitoring RouterRemote Connection Information Ethernet Interface InformationSystem Information IP Routing InformationPPPoE Session DiagnosticsRouting Table Information Interface InformationMemory Usage Files InformationTCP/IP Statistics List All Configuration Data