Cisco SRP521W-K9-G1 Administration Guide - Page 187

Configuring VPN, IPSec Policy Settings, Manual Policy Parameters

Page 187 highlights

Configuring VPN IPSec Policy 7 IPSec Policy Settings Auto Policy Parameters (options only appear if Auto Policy is selected) PFS Select Enable to enable Perfect Forward Secrecy (PFS). The default is disabled. This feature requires a new Diffie-Hellman exchange for each phase-2 negotiation. While this process is slower, it ensures that no keys are dependent on any other previously used keys. SA Lifetime Enter the IPSec SA life time in seconds. The default is 7800 (130 minutes). Manual Policy Parameters (options only appear if Manual Policy is selected) SPI Incoming Enter a hexidecimal value, for the incoming Security Parameters Index between 0x100 and 0xffffffff. SPI Outgoing Enter a hexdicimal value, for the outgoing Security Parameters Index between 0x100 and 0xffffffff. Encryption Algorithm Key Enter a hexidecimal value for the encryption algorithm key. The length depends on the Encryption Algorithm that you selected. For example, the key length for 3DES is 48 hexadecimal digits. Integrity Algorithm Key Enter a hexadecimal value for the integrity algorithm key. The length of the key depends on the Integrity Algorithm selected. For example, MD5 is 32 hexadecimal digits and SHA-1 is 40 hexadecimal digits. Local Traffic Selection Local IP/IP Address/ Determine which local hosts will be allowed to use the Subnet Mask VPN. Select either a single IP Address, or a subnet (IP Address and Subnet Mask). Remote Traffic Selection Remote IP/IP Address/Subnet Mask Traffic from permitted local hosts to the remote IP address or subnet will be routed via the VPN tunnel. Select either a single IP Address, or a subnet (IP Address and Subnet Mask). Select IKE Policy Choose an IKE Policy to associate with this IPSec Policy. To view all the IKE policies, Click View IKE Table. Cisco SRP500 Series Services Ready Platforms Administration Guide (SRP520 Models) 187

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229

Configuring VPN
IPSec Policy
Cisco SRP500 Series Services Ready Platforms Administration Guide (SRP520 Models)
187
7
Auto Policy Parameters (options only appear if Auto Policy is selected)
PFS
Select
Enable
to enable Perfect Forward Secrecy (PFS).
The default is disabled. This feature requires a new
Diffie-Hellman exchange for each phase-2 negotiation.
While this process is slower, it ensures that no keys are
dependent on any other previously used keys.
SA Lifetime
Enter the IPSec SA life time in seconds. The default is
7800
(130 minutes).
Manual Policy Parameters
(options only appear if Manual Policy is
selected)
SPI Incoming
Enter a hexidecimal value, for the incoming Security
Parameters Index between 0x100 and 0xffffffff.
SPI Outgoing
Enter a hexdicimal value, for the outgoing Security
Parameters Index between 0x100 and 0xffffffff.
Encryption
Algorithm Key
Enter a hexidecimal value for the encryption algorithm
key. The length depends on the Encryption Algorithm
that you selected. For example, the key length for 3DES
is 48 hexadecimal digits.
Integrity Algorithm
Key
Enter a hexadecimal value for the integrity algorithm key.
The length of the key depends on the Integrity Algorithm
selected. For example, MD5 is 32 hexadecimal digits
and SHA-1 is 40 hexadecimal digits.
Local Traffic Selection
Local IP/IP Address/
Subnet Mask
Determine which local hosts will be allowed to use the
VPN. Select either a single IP Address, or a subnet (IP
Address and Subnet Mask).
Remote Traffic Selection
Remote IP/IP
Address/Subnet
Mask
Traffic from permitted local hosts to the remote IP
address or subnet will be routed via the VPN tunnel.
Select either a
single IP Address
, or a
subnet
(IP
Address and Subnet Mask).
Select IKE Policy
Choose an IKE Policy to associate with this IPSec Policy.
To view all the IKE policies, Click
View IKE Table
.
IPSec Policy Settings