HP 8/20q HP StorageWorks Simple SAN Connection Manager User Guide (5697-0460, - Page 63

Cancel, HMAC-MD5, HMAC-SHA1, AES-XCBC-MAC, ESP-old, DES-CBC, Blowfish-CBC

Page 63 highlights

Authentication Select one of the following methods to use to authenticate the source and destination address: Authentication Key (xx) • HMAC-MD5-Hash Message Authentication Code Message-Digest Algorithm 5 • HMAC-SHA1-Hash Message Authentication Code Secure Hash Algorithm 1 • HMAC-SHA256-Hash Message Authentication Code Secure Hash Algorithm 1 • AES-XCBC-MAC-Advanced Encryption Standard Extensions Cipher Block Chaining Message Authentication Code • None-Do not authenticate source and destination address Enter a string of hexadecimal bytes or a quoted string of characters that is converted into hexadecimal ASCII bytes. The allowed lengths (indicated by xx in the box label) for each authentication method are as follows: Encryption • For HMAC-MD5-16 bytes • For HMAC-SHA1-20 bytes • For HMAC-SHA256-32 bytes • For AES-XCBC-MAC-16 bytes (Required if you select ESP or ESP-old for the Protocol) Select one of the following methods used to encrypt outbound data or decrypt inbound data: Encryption Key (xx) • DES-CBC-Data Encryption Standard Cipher Block Chaining • 3DES-CBC-Triple Data Encryption Standard Cipher Block Chaining • NULL-NULL encryption algorithm • Blowfish-CBC-Blowfish Cipher Block Chaining • AES-CBC-Advanced Encryption Standard Cipher Block Chaining • Twofish-CBC-Twofish Cipher Block Chaining (Required if you select ESP or ESP-old for the Protocol) Enter a string of bytes or a quoted string of characters that is converted into hexadecimal ASCII bytes. The allowed lengths (indicated by xx in the box label) for each encryption method are as follows: • For DES-CBC-8 bytes • For 3DES-CBC-24 bytes • For NULL-no key required • For Blowfish CBC-5-56 bytes • For AES-CBC-16/24/32 bytes • For Twofish-CBC-16-32 bytes NOTE: IPsec associations must be unique. The unique key for an association includes the fields Destination Address, Protocol, and SPI. No two IPsec associations can contain duplicate values in these three fields. 4. To save the new IPsec association and close the IPsec Association dialog box, click OK. To abandon creation of the IPsec association, click Cancel. 5. When you are through managing security associations, select one of the following options: • To save your changes and close the IPsec Configuration dialog box, click OK. • To close the IPsec Configuration dialog box without saving any changes, click Cancel. HP StorageWorks Simple SAN Connection Manager User Guide 63

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150

HP StorageWorks Simple SAN Connection Manager User Guide
63
NOTE:
IPsec associations must be unique. The unique key for an association includes the fields
Destination Address, Protocol, and SPI. No two IPsec associations can contain duplicate values in
these three fields.
4.
To save the new IPsec association and close the IPsec Association dialog box, click
OK
. To abandon
creation of the IPsec association, click
Cancel
.
5.
When you are through managing security associations, select one of the following options:
To save your changes and close the IPsec Configuration dialog box, click
OK
.
To close the IPsec Configuration dialog box without saving any changes, click
Cancel
.
Authentication
Select one of the following methods to use to authenticate the source and
destination address:
HMAC-MD5
—Hash Message Authentication Code Message-Digest
Algorithm 5
HMAC-SHA1
—Hash Message Authentication Code Secure Hash Algorithm 1
HMAC-SHA256
—Hash Message Authentication Code Secure Hash
Algorithm 1
AES-XCBC-MAC
—Advanced Encryption Standard Extensions Cipher Block
Chaining Message Authentication Code
None
—Do not authenticate source and destination address
Authentication Key
(
xx
)
Enter a string of hexadecimal bytes or a quoted string of characters that is
converted into hexadecimal ASCII bytes. The allowed lengths (indicated by
xx
in
the box label) for each authentication method are as follows:
For HMAC-MD5—16 bytes
For HMAC-SHA1—20 bytes
For HMAC-SHA256—32 bytes
For AES-XCBC-MAC—16 bytes
Encryption
(Required if you select
ESP
or
ESP-old
for the Protocol) Select one of the following
methods used to encrypt outbound data or decrypt inbound data:
DES-CBC
—Data Encryption Standard Cipher Block Chaining
3DES-CBC
—Triple Data Encryption Standard Cipher Block Chaining
NULL
—NULL encryption algorithm
Blowfish-CBC
—Blowfish Cipher Block Chaining
AES-CBC
—Advanced Encryption Standard Cipher Block Chaining
Twofish-CBC
—Twofish Cipher Block Chaining
Encryption Key (
xx
)
(Required if you select
ESP
or
ESP-old
for the Protocol) Enter a string of bytes or a
quoted string of characters that is converted into hexadecimal ASCII bytes. The
allowed lengths (indicated by
xx
in the box label) for each encryption method
are as follows:
For DES-CBC—8 bytes
For 3DES-CBC—24 bytes
For NULL—no key required
For Blowfish CBC—5–56 bytes
For AES-CBC—16/24/32 bytes
For Twofish-CBC—16–32 bytes