Table 1 IPsec Parameters on Windows and
Parameter | Windows Configuration | Notes | |
IKE Preshared Key | Specify it in the | Specify it using the |
|
| Authentication Methods for |
| |
| a rule. | the ipsec_config add |
|
|
| auth command. |
|
IKE Exchange Type | Windows supports only | Specify it using the |
|
| Main Mode exchanges. |
| |
|
| the ipsec_config add |
|
|
| auth command. The |
|
|
| default value is MM (Main |
|
|
| Mode). |
|
Maximum IKE SA Lifetime, | Specify it in the Key | Specify it using | The Windows IP Security |
measured by time | Exchange Settings dialog | argument in the | Policy |
| box. (To navigate to the Key | ipsec_config add ike | minutes as the time unit. |
| Exchange Setting dialog | command. | The |
| box, select the General tab |
| command uses seconds as |
| in the Policy Properties |
| the time unit. See “IKE SA |
| dialog box, then select |
| |
| Advanced settings.) |
| |
|
|
| additional information. |
Maximum Quick Mode | Specify it in the Key | Specify it using | See “Maximum Quick |
(QM) negotiations per IKE | Exchange Settings dialog | argument in the | Modes” (page 43) for |
SA | box. (To navigate to the Key | ipsec_config add ike | additional information. |
| Exchange Setting dialog | command. |
|
| box, select the General tab |
|
|
| in the Policy Properties |
|
|
| dialog box, then select |
|
|
| Advanced settings.) |
|
|
Perfect Forward Secrecy | Windows supports PFS for |
(PFS) | keys only (PFS for session |
| keys) and supports PFS for |
| keys in conjunction with |
| PFS for all identities (PFS |
| for master keys). |
| Specify PFS for master keys |
| in the Key Exchange |
| Settings dialog box. (To |
| navigate to the Key |
| Exchange Setting dialog |
| box, select the General tab |
| in the Policy Properties |
| dialog box, then select |
| Advanced settings.) |
Specify PFS for master keys using
ipsec_config add ike command.
See “Perfect Forward Secrecy (PFS)” (page 43) for more information.
IKE SA Proposals | Specify it in the General |
| parameters for a policy. You |
| can configure multiple IKE |
| SA proposals and their |
| preference order. |
You can specify the parameters for one IKE SA proposal in an IKE policy, using the
ipsec_config add ike
command.
See “IKE Parameter Selection” (page 42) for additional information.
Microsoft filters can be mirrored
Source address: 10.1.1.1
Destination address: 10.2.2.2
Comparing