Konica Minolta bizhub 4000i bizhub 5000i/4000i User Guide - Page 173

Remote Router IP-Address, IKEv2 Medium Security

Page 173 highlights

Use Prefixed Template Select Custom, IKEv2 High Security, or IKEv2 Medium Security. The setting items are different depending on the selected template. Internet Key Exchange (IKE) IKE is a communication protocol that is used to exchange encryption keys in order to carry out encrypted communication using IPsec. To carry out encrypted communication for that time only, the encryption algorithm that is necessary for IPsec is determined and the encryption keys are shared. For IKE, the encryption keys are exchanged using the Diffie-Hellman key exchange method, and encrypted communication that is limited to IKE is carried out. If you selected Custom in Use Prefixed Template, select IKEv2. Authentication Type Configure the IKE authentication and encryption. • Diffie-Hellman Group This key exchange method allows secret keys to be securely exchanged over an unprotected network. The Diffie-Hellman key exchange method uses a discrete logarithm problem, not the secret key, to send and receive open information that was generated using a random number and the secret key. Select Group1, Group2, Group5, or Group14. • Encryption Select DES, 3DES, AES-CBC 128, or AES-CBC 256. • Hash Select MD5, SHA1, SHA256, SHA384 or SHA512. • SA Lifetime Specify the IKE SA lifetime. Type the time (seconds) and number of kilobytes (KByte). Encapsulating Security • Protocol Select ESP. ESP is a protocol for carrying out encrypted communication using IPsec. ESP encrypts the payload (communicated contents) and adds additional information. The IP packet is comprised of the header and the encrypted payload, which follows the header. In addition to the encrypted data, the IP packet also includes information regarding the encryption method and encryption key, the authentication data, and so on. • Encryption Select DES, 3DES, AES-CBC 128, or AES-CBC 256. • Hash Select MD5, SHA1, SHA256, SHA384, or SHA512. • SA Lifetime Specify the IPsec SA lifetime. Type the time (seconds) and number of kilobytes (KByte) before the IPsec SA will expire. • Encapsulation Mode Select Transport or Tunnel. • Remote Router IP-Address Type the IP address (IPv4 or IPv6) of the remote router. Enter this information only when the Tunnel mode is selected. 169

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317

Use Prefixed Template
Select
Custom
,
IKEv2 High Security
, or
IKEv2 Medium Security
. The setting items are different depending
on the selected template.
Internet Key Exchange (IKE)
IKE is a communication protocol that is used to exchange encryption keys in order to carry out encrypted
communication using IPsec. To carry out encrypted communication for that time only, the encryption algorithm
that is necessary for IPsec is determined and the encryption keys are shared. For IKE, the encryption keys are
exchanged using the Diffie-Hellman key exchange method, and encrypted communication that is limited to
IKE is carried out.
If you selected
Custom
in
Use Prefixed Template
, select
IKEv2
.
Authentication Type
Configure the IKE authentication and encryption.
Diffie-Hellman Group
This key exchange method allows secret keys to be securely exchanged over an unprotected network.
The Diffie-Hellman key exchange method uses a discrete logarithm problem, not the secret key, to send
and receive open information that was generated using a random number and the secret key.
Select
Group1
,
Group2
,
Group5
, or
Group14
.
Encryption
Select
DES
,
3DES
,
AES-CBC 128
, or
AES-CBC 256
.
Hash
Select
MD5
,
SHA1
,
SHA256
,
SHA384
or
SHA512
.
SA Lifetime
Specify the IKE SA lifetime.
Type the time (seconds) and number of kilobytes (KByte).
Encapsulating Security
Protocol
Select
ESP
.
ESP is a protocol for carrying out encrypted communication using IPsec. ESP encrypts the payload
(communicated contents) and adds additional information. The IP packet is comprised of the header and
the encrypted payload, which follows the header. In addition to the encrypted data, the IP packet also
includes information regarding the encryption method and encryption key, the authentication data, and so
on.
Encryption
Select
DES
,
3DES
,
AES-CBC 128
, or
AES-CBC 256
.
Hash
Select
MD5
,
SHA1
,
SHA256
,
SHA384
, or
SHA512
.
SA Lifetime
Specify the IPsec SA lifetime.
Type the time (seconds) and number of kilobytes (KByte) before the IPsec SA will expire.
Encapsulation Mode
Select
Transport
or
Tunnel
.
Remote Router IP-Address
Type the IP address (IPv4 or IPv6) of the remote router. Enter this information only when the
Tunnel
mode is selected.
169