
Page layout with additional Descriptors
IPSec Security
Descriptor
Page layout with additional Descriptors
Chapter 3
Configuration via Local Pages
When you click Specify Additional Descriptors, the IKE Security Descriptors area of the page is updated and shows additional fields where you can specify up to four alternative IKE Security Descriptors:
These will be used as alternative valid proposals in the IKE negotiations.
The IPSec Security Descriptor bundles the security parameters used for the Phase 2 Security Association.
A number of IPSec Security Descriptors are
In the example shown above, the
This descriptor contains following settings:
Parameter | Example: DES_MD5_TUN |
|
|
Cryptographic function | DES |
|
|
Hash function | |
|
|
Use of Perfect Forward Secrecy | no |
|
|
IPSec SA lifetime in seconds. | 86400 seconds (= 24 hours) |
|
|
IPSec SA volume lifetime in kbytes. | no volume limit |
|
|
The ESP encapsulation mode | tunnel |
|
|
The contents of the IPSec Security Descriptors can be verified via
Advanced > Connections > Security Descriptors.
When you click Specify Additional Descriptors, the IPSEC Security Descriptors area of the page is updated and shows additional fields where you can specify up to four alternative IPSec Security Descriptors:
These will be used as alternative valid proposals in the Phase 2 negotiations.
67 | |
|