Cisco SRP521W-K9-G1 Administration Guide - Page 186

Manual, Submit, General Settings, Auto Policy, Site to Site IPSec, VPN > IKE Policy, IP Address

Page 186 highlights

Configuring VPN IPSec Policy 7 STEP 6 Choose a policy type from the drop-down list. You can select from Auto or Manual. STEP 7 Enter the IPSec Policy settings as defined in the IPSec Policy Settings table. STEP 8 Click Submit to save your settings. The VPN policy appears in the List of IKE policies on the IKE Policy Add Entry page. IPSec Policy Settings General Settings Policy Name Enter a unique name for the VPN Policy. Policy Type Choose the policy type. Select from Auto Policy or Manual Policy. The Auto Policy uses the IKE protocol to negotiate random keys for more security. If you choose this option, you must also set an IKE policy on the Site to Site IPSec VPN > IKE Policy page The Manual Policy does not use IKE, which makes this policy more simple, but less secure. Remote Endpoint Choose how you want to identify the remote gateway for this site-to-site VPN tunnel. Select IP Address to enter an IP address, select FQDN to enter a Fully Qualified Domain Name, or select Any (available only for an Auto Policy). Be aware that an FQDN requires that the SRP can connect to a DNS server to resolve the address before establishing the VPN tunnel. Encryption Algorithm Choose the encryption algorithm. Select from DES (8 characters), 3DES (24 characters), AES-128 (16 characters) AES192 (24 characters) and AES256 (32 characters). Integrity Algorithm Choose an integrity algorithm. Select from MD5 (16 characters) or SHA-1 (20 characters). Cisco SRP500 Series Services Ready Platforms Administration Guide (SRP520 Models) 186

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229

Configuring VPN
IPSec Policy
Cisco SRP500 Series Services Ready Platforms Administration Guide (SRP520 Models)
186
7
STEP
6
Choose a policy type from the drop-down list. You can select from
Auto
or
Manual
.
STEP
7
Enter the IPSec Policy settings as defined in the
IPSec Policy Settings
table.
STEP
8
Click
Submit
to save your settings.
The VPN policy appears in the List of IKE policies on the IKE Policy Add Entry
page.
IPSec Policy Settings
General Settings
Policy Name
Enter a unique name for the VPN Policy.
Policy Type
Choose the policy type. Select from
Auto Policy
or
Manual
Policy.
The Auto Policy uses the IKE protocol to negotiate
random keys for more security. If you choose this option,
you must also set an IKE policy on the
Site to Site IPSec
VPN > IKE Policy
page The Manual Policy does not use
IKE, which makes this policy more simple, but less
secure.
Remote Endpoint
Choose how you want to identify the remote gateway
for this site-to-site VPN tunnel.
Select
IP Address
to enter an IP address, select
FQDN
to enter a Fully Qualified Domain Name, or select
Any
(available only for an Auto Policy). Be aware that an
FQDN requires that the SRP can connect to a DNS
server to resolve the address before establishing the
VPN tunnel.
Encryption
Algorithm
Choose the encryption algorithm. Select from
DES
(8
characters),
3DES
(24 characters),
AES-128
(16
characters)
AES192
(24 characters) and
AES256
(32 characters).
Integrity Algorithm
Choose an integrity algorithm. Select from
MD5
(16
characters)
or
SHA-1
(20 characters).