Prestige 652 ADSL Security Router

 

 

 

Menu 27.1.1.1 - IKE Setup

 

 

 

 

 

 

 

 

 

 

 

 

Phase 1

 

 

 

 

 

 

 

Negotiation Mode= Main

 

 

 

 

 

 

Pre-Shared Key= ?

 

 

 

 

 

 

Encryption Algorithm = DES

 

 

 

 

 

 

Authentication Algorithm = MD5

 

 

 

 

 

 

SA Life Time (Seconds)= 28800

 

 

 

 

 

 

Key Group= DH1

 

 

 

 

 

 

 

Phase 2

= ESP

 

 

 

 

 

 

Active Protocol

 

 

 

 

 

 

Encryption Algorithm = DES

 

 

 

 

 

 

Authentication Algorithm = SHA1

 

 

 

 

 

 

SA Life Time (Seconds)= 28800

 

 

 

 

 

 

Encapsulation

= Tunnel

 

 

 

 

 

 

Perfect Forward Secrecy (PFS)= None

 

 

 

 

 

 

Press ENTER to Confirm or ESC to Cancel:

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Figure 25-9Menu 27.1.1.1 IKE Setup

 

 

 

 

 

 

Table 25-5Menu 27.1.1.1 IKE Setup

 

 

 

 

 

 

 

 

 

 

 

 

 

FIELD

 

DESCRIPTION

EXAMPLE

Phase 1

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Negotiation

Press [SPACE BAR] to choose from Main or Aggressive and then press

Main

 

 

Mode

[ENTER]. See earlier for a discussion of these modes. Multiple SAs

 

 

 

 

 

 

connecting through a secure gateway must have the same negotiation

 

 

 

 

 

 

mode.

 

 

 

 

Pre-Shared Key

Prestige gateways authenticate an IKE VPN session by matching pre-shared

 

 

 

 

 

 

keys. Pre-shared keys are best for small networks with fewer than ten nodes.

 

 

 

 

 

 

Enter your pre-shared key here. Enter up to 31 characters. Any character

 

 

 

 

 

 

may be used, including spaces, but trailing spaces are truncated. Multiple

 

 

 

 

 

 

SAs connecting through a secure gateway must have the same pre-shared

 

 

 

 

 

 

key.

 

 

 

 

 

 

 

 

 

 

 

 

 

Encryption

When DES is used for data communications, both sender and receiver must

DES

 

 

Algorithm

know the same secret key, which can be used to encrypt and decrypt the

 

 

 

 

 

 

message or to generate and verify a message authentication code. Prestige

 

 

 

 

 

 

DES encryption algorithm uses a 56-bit key.

 

 

 

 

 

 

Triple DES (3DES), is a variation on DES that uses a 168-bit key. As a

 

 

 

 

 

 

result, 3DES is more secure than DES. It also requires more processing

 

 

 

 

 

 

power, resulting in slightly increased latency and decreased throughput.

 

 

 

VPN/IPSec Setup

25-15