TCGID

[Siemens] Trust Center Global ID

The attribute/value pairs must be of the form attribute=value and be separated by commas. For example : C=US, ST=Illinois, L=Chicago, O=CyberGuard, OU=Sales, CN=SG550. It must match exactly the Distinguished Name of the remote party's local certificate to successfully authenticate the tunnel. This field appears when x.509 Certificates has been selected.

Generate an RSA key of pull down menu allows the length of the CyberGuard SG appliance generated RSA public/private key pair to be specified. The options include 512, 1024, 1536 and 2048 bits. The greater the key pair length, the longer the time required to generate the keys. It may take up to 20 minutes for a 2048 bit RSA key to be generated. This option appears when RSA Digital Key Signatures has been selected.

SPI Number field is the Security Parameters Index. However, this applies to the remote party. It is a hexadecimal value and must be unique. It is used to establish and uniquely identify the tunnel. It must be of the form 0xhex, where hex is one or more hexadecimal digits and be in the range of 0x100-0xfff. This field appears when Manual Keying has been selected.

Authentication Key field is the ESP Authentication Key. However, this applies to the remote party. It must be of the form 0xhex, where hex is one or more hexadecimal digits. The hex part must be exactly 32 characters long when using MD5 or 40 characters long when using SHA1 (excluding any underscore characters). It must use the same hash as the CyberGuard SG appliance's authentication key. This field appears when Manual Keying has been selected.

Encryption Key field is the ESP Encryption Key. However, this applies to the remote party. It must be of the form 0xhex, where hex is one or more hexadecimal digits. The hex part must be exactly 16 characters long when using DES or 48 characters long when using 3DES (excluding any underscore characters). It must use the same cipher as the CyberGuard SG appliance's encryption key. This field appears when Manual Keying has been selected.

Remote Network is the network behind the remote party. This field appears when Manual Keying has been selected.

128

Virtual Private Networking

Page 132
Image 132
SnapGear 2.0.1 user manual Tcgid, Virtual Private Networking