Prestige 2602H/HW Series User’s Guide
Figure 264 Menu 27.1.1.1KE Setup
Menu 27.1.1.1 - IKE Setup
Phase 1
Negotiation Mode= Main
PSK=
Encryption Algorithm = AES
Authentication Algorithm = SHA1
SA Life Time (Seconds)= 28800
Key Group= DH1
Phase 2
Active Protocol = ESP
Encryption Algorithm = AES
Authentication Algorithm = MD5
SA Life Time (Seconds)= 28800
Encapsulation = Tunnel
Perfect Forward Secrecy (PFS)= None
Press ENTER to Confirm or ESC to Cancel:
The following table describes the fields in this menu.
Table 149 Menu 27.1.1.1 IKE Setup
FIELD | DESCRIPTION |
|
|
Phase 1 |
|
|
|
Negotiation | Press [SPACE BAR] to choose from Main or Aggressive and then press [ENTER]. |
Mode | See earlier for a discussion of these modes. Multiple SAs connecting through a |
| secure gateway must have the same negotiation mode. |
PSK | Prestige gateways authenticate an IKE VPN session by matching |
| |
| |
| spaces, but trailing spaces are truncated. |
| Both ends of the VPN tunnel must use the same |
| “PYLD_MALFORMED” (payload malformed) packet if the same |
| used on both ends. |
Encryption | The Prestige and the remote IPSec router generate an encryption key from the Diffie- |
Algorithm | Hellman key exchange. Prestige DES encryption algorithm uses a |
| Triple DES (3DES), is a variation on DES that uses a |
| more secure than DES. It also requires more processing power, resulting in slightly |
| increased latency and decreased throughput. |
| This implementation of AES uses a |
| Press [SPACE BAR] to choose from DES, 3DES or AES and then press [ENTER]. |
|
|
Authentication | MD5 (Message Digest 5) and SHA1 (Secure Hash Algorithm) are hash algorithms |
Algorithm | used to authenticate packet data. The SHA1 algorithm is generally considered |
| stronger than MD5, but is slightly slower. |
| Press [SPACE BAR] to choose from SHA1 or MD5 and then press [ENTER]. |
|
|
SA Life Time | Define the length of time before an IKE Security Association automatically |
(Seconds) | renegotiates in this field. It may range from 60 to 3,000,000 seconds (almost 35 days). |
| A short SA Life Time increases security by forcing the two VPN gateways to update |
| the encryption and authentication keys. However, every time the VPN tunnel |
| renegotiates, all users accessing remote resources are temporarily disconnected. |
Chapter 43 VPN/IPSec Setup | 431 |