
Prestige 652 ADSL Security Router
FigureIn phase 1 you must:
¾Choose a negotiation mode.
¾Authenticate the connection by entering a
¾Choose an encryption algorithm.
¾Choose an authentication algorithm.
¾Choose a
¾Set the IKE SA lifetime. This field allows you to determine how long IKE SA negotiation
should proceed before it times out. A value of 0 means IKE SA negotiation never times out. If IKE SA negotiation times out, then both IKE SA and IPSec SA must be renegotiated.
In phase 2 you must:
¾Choose which protocol to use (ESP or AH) for the IKE key exchange.
¾Choose an encryption algorithm.
¾Choose an authentication algorithm
¾Choose whether to enable Perfect Forward Secrecy (PFS) using
¾Choose Tunnel mode or Transport mode.
¾Set the IPSec SA lifetime. This field allows you to determine how long IPSec SA setup should proceed before it times out. A value of 0 means IPSec SA never times out. If IPSec SA negotiation times out, then the IPSec SA must be renegotiated (but not the IKE SA).
25.5.2Negotiation Mode
The phase 1 Negotiation Mode you select determines how the Security Association (SA) will be established for each connection through IKE negotiations.
¾Main Mode ensures the highest level of security when the communicating parties are negotiating authentication (phase 1). It uses 6 messages in three round trips (SA negotiation,
VPN/IPSec Setup |