7 Tunneling Protocols
7-20 VPN 3000 Concentrator Series User Guide
Figure 7-10: Configuration | System | Tunneling Protocols | IPSec | IKE Proposals screen
Cisco supplies default IKE proposals that you can use or modify; see Table 7-1. See Configuration | System
| Tunneling Protocols | IPSec | IKE Proposals | Add for explanations of the parameters.
Table 7-1: Cisco-supplied default IKE Proposals
ProposalNameParameter
IKE-3DES
-MD5
IKE-3DES
-MD5-DH1
IKE-DES
-MD5
IKE-3DES-MD5-RSA
IKE-3DES
-SHA-DSA
IKE-3DES-MD5-RSA-DH1
Active by
default
Active by
default
Active by
default
Inactive by
default
Inactive by
default
Inactive by
default
Authentication
Mode
Preshared Keys Preshared Keys Preshared Keys RSA Digital
Certificate
DSA Digital
Certificate
RSA Digital
Certificate
Authentication
Algorithm
MD5/
HMAC-128
MD5/
HMAC-128
MD5/
HMAC-128
MD5/
HMAC-128
SHA/HMAC-160 MD5/
HMAC-128
Encryption
Algorithm
3DES-168 3DES-168 DES-56 3DES-168 3DES-168 3DES-168
Diffie-Hellman
Group
Group 2
(1024-bits)
Group 1
(768-bits)
Group 1
(768-bits)
Group 2
(1024-bits)
Group 2
(1024-bits)
Group 1
(768-bits)
Lifetime
Measurement
Time Time Tim e Time Time Tim e
Data Lifetime 10000 KB
(not relevant)
10000 KB
(not relevant)
10000 KB
(not relevant)
10000 KB
(not relevant)
10000 KB
(not relevant)
10000 KB
(not relevant)
Time Li fet ime 86400 sec 86400 sec 86400 sec 86400 sec 86400 sec 86400 sec