Configure Security

 

 

 

 

Section

Field Description

 

 

Key

Select one of the following options for the key exchange method:

 

(continued)Management

Auto (IKE)

 

 

 

Encryption: The Encryption method determines the length of the key used

 

 

 

to encrypt/decrypt ESP packets. Notice that both sides must use the same

 

 

 

method.

 

 

 

Authentication: The Authentication method authenticates the

 

 

 

Encapsulating Security Payload (ESP) packets. Select MD5 or SHA. Notice

 

 

 

that both sides (VPN endpoints) must use the same method.

 

 

 

MD5: A one-way hashing algorithm that produces a 128-bit digest

 

 

 

SHA: A one-way hashing algorithm that produces a 160-bit digest

 

 

 

Perfect Forward Secrecy (PFS): If PFS is enabled, IKE Phase 2 negotiation

 

 

 

will generate new key material for IP traffic encryption and authentication.

 

 

 

Note that both sides must have PFS enabled.

 

 

 

Pre-Shared Key: IKE uses the Pre-Shared Key to authenticate the remote

 

 

 

IKE peer. Both character and hexadecimal values are acceptable in this

 

 

 

field, e.g., "My_@123" or "0x4d795f40313233". Note that both sides must use

 

 

 

the same Pre-Shared Key.

 

 

 

Key Lifetime: This field specifies the lifetime of the IKE generated key. If

 

 

 

the time expires, a new key will be renegotiated automatically. The Key

 

 

 

Lifetime may range from 300 to 100,000,000 seconds. The default lifetime is

 

 

 

3600 seconds.

 

 

Manual

 

 

 

Encryption: The Encryption method determines the length of the key used

 

 

 

to encrypt/decrypt ESP packets. Notice that both sides must use the same

 

 

 

method.

 

 

 

Encryption Key: This field specifies a key used to encrypt and decrypt IP

 

 

 

traffic. Both character and hexadecimal values are acceptable in this field.

 

 

 

Note that both sides must use the same Encryption Key.

 

 

 

Authentication: The Authentication method authenticates the

 

 

 

Encapsulating Security Payload (ESP) packets. Select MD5 or SHA. Notice

 

 

 

that both sides (VPN endpoints) must use the same method.

 

 

 

MD5: A one-way hashing algorithm that produces a 128-bit digest

 

 

 

SHA: A one-way hashing algorithm that produces a 160-bit digest

 

 

 

Authentication Key: This field specifies a key used to authenticate IP

 

 

 

traffic. Both character and hexadecimal values are acceptable in this field.

 

 

 

Note that both sides must use the same Authentication Key.

 

 

 

Inbound SPI/Outbound SPI: The Security Parameter Index (SPI) is carried

 

 

 

in the ESP header. This enables the receiver to select the SA, under which a

 

 

 

packet should be processed. The SPI is a 32-bit value. Both decimal and

 

 

 

hexadecimal values are acceptable. e.g., "987654321" or "0x3ade68b1". Each

 

 

 

tunnel must have a unique Inbound SPI and Outbound SPI. No two tunnels

 

 

 

share the same SPI. Note that the Inbound SPI must match the remote

 

 

 

gateway's Outbound SPI, and vice versa.

 

 

 

 

 

60

 

 

4021192 Rev B

Page 60
Image 60
Cisco Systems DPC3925, EPC3925, 4031761, 4031762, 4033836 Section Field Description Key, Auto IKE, Manual

4031761, 4033836, DPC3925, 4031762, EPC3925 specifications

Cisco Systems is a leading global technology company known for its networking hardware, software, and telecommunication equipment. Among its expansive product line, the DPQ2160 DOCSIS 2.0 modem series and the EPC3925 are significant models utilized in various internet service delivery scenarios.

The DPQ2160 is a DOCSIS 2.0 compliant modem that offers an efficient solution for cable internet services. It features an advanced design to enhance data transfer rates and is compatible with both downstream and upstream channels. With a maximum downstream data rate of 38 Mbps, this modem supports high-speed internet access ideal for home and small business environments. It also ensures reliable connectivity through its robust channel bonding capabilities, which allow multiple data streams. Additionally, the DPQ2160 integrates a user-friendly web interface for easy management and configuration, making it simple for users to troubleshoot and monitor their connection.

Cisco’s EPC3925 is a versatile gateway that satisfies both broadband connectivity and Wi-Fi needs. It combines DOCSIS 3.0 capabilities, enabling high-definition video streaming, online gaming, and other bandwidth-intensive applications. The EPC3925 supports various wireless standards, including 802.11n, providing a strong and reliable Wi-Fi connection throughout homes or offices. Its dual-band feature ensures users can connect multiple devices while minimizing interference. Furthermore, the EPC3925 offers advanced security features, including built-in firewall capabilities and support for Wi-Fi Protected Access (WPA) encryption, which safeguards users' networks.

Both the DPQ2160 and EPC3925 incorporate technologies aimed at improving user experience. They are designed for easy setup, often featuring plug-and-play capabilities that allow for rapid installation without the need for extensive configuration knowledge. Cisco’s emphasis on quality and reliability ensures that these devices consistently provide the performance required in today’s data-driven world.

The models also demonstrate strong backward compatibility with earlier DOCSIS versions, ensuring that users can maintain their internet service even if they have older infrastructure. This versatility is vital for service providers, allowing them to deploy these devices in various scenarios with minimum disruption.

Overall, Cisco's DPQ2160 and EPC3925 modems reflect the company’s commitment to driving connectivity and communication innovations, providing users with essential tools for navigating an increasingly online world. With advanced features and robust performance, these devices exemplify Cisco's dedication to ensuring seamless and secure internet access.