Xerox 6400XF WorkCentre 6400 System Administrator Guide - Page 68

Editing or Deleting an Action

Page 68 highlights

Security Note: DH is a public-key cryptography scheme that allows two parties to establish a shared secret over an insecure communications channel. It is also used within IKE to establish session keys. 2. Select the DH Group. Options are: • Group 2: Provides a 1024-bit Modular Exponential (MODP) keying strength. • Group 14: Provides a 2048-bit MODP keying strength. 3. Select one or more of the following Hash - Encryption algorithms: • SHA1 - Advanced Encryption Standard (AES) • SHA1 - Triple Data Encryption Standard (3DES) • MD5 - AES • MD5 - 3DES Notes: • 3DES is a variation on DES that uses a168-bit key. 3DES is more secure than DES. • AES is more secure than 3DES. 4. Under IKE Phase 2, select the IPsec Mode. Options are Transport Mode or Tunnel Mode. Note: Transport mode only encrypts the IP payload whereas Tunnel mode encrypts the IP header and the IP payload. Tunnel mode provides protection for an entire IP packet by treating it as an Authentication Header (AH), or Encapsulating Security Payload (ESP). 5. If you select Tunnel Mode, under Enable Security End Point Address, select the address type. Options are Disabled, IPv4 Address, or IPv6 Address. 6. Under IPsec Security, select ESP, AH, or BOTH. 7. Type the Key Lifetime, and select the units; Seconds, Minutes, or Hours. 8. Under Perfect Forward Secrecy (PFS), select None, Group 2, or Group 14. Note: PFS is disabled by default. PFS allows faster IPSec setup, but is not very secure. 9. Under Hash, select from the following: • SHA1 • MD5 • None 10. If you selected ESP or BOTH for the IPsec Security type, select one or more of the following Encryption types: Note: Encryption will not display if IPsec Security is set to AH. • AES • 3DES • Null 11. Click Save. Editing or Deleting an Action To edit or delete an action, select the action from the list, then click Edit or Delete. 68 WorkCentre 6400 Multifunction Printer System Administrator Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184

Security
WorkCentre 6400 Multifunction Printer
System Administrator Guide
68
Note:
DH is a public-key cryptography scheme that allows two parties to establish a shared secret
over an insecure communications channel. It is also used within IKE to establish session keys.
2.
Select the
DH Group
. Options are:
Group 2: Provides a 1024-bit Modular Exponential (MODP) keying strength.
Group 14: Provides a 2048-bit MODP keying strength.
3.
Select one or more of the following
Hash - Encryption
algorithms:
SHA1 - Advanced Encryption Standard (AES)
SHA1 - Triple Data Encryption Standard (3DES)
MD5 - AES
MD5 - 3DES
Notes:
3DES is a variation on DES that uses a168-bit key. 3DES is more secure than DES.
AES is more secure than 3DES.
4.
Under
IKE Phase 2
, select the
IPsec Mode
.
Options are
Transport Mode
or
Tunnel Mode
.
Note:
Transport mode only encrypts the IP payload whereas Tunnel mode encrypts the IP header
and the IP payload. Tunnel mode provides protection for an entire IP packet by treating it as an
Authentication Header (AH), or Encapsulating Security Payload (ESP).
5.
If you select
Tunnel Mode
, under
Enable Security End Point Address
, select the address type.
Options are
Disabled
,
IPv4 Address
, or
IPv6 Address
.
6.
Under
IPsec Security
, select
ESP
,
AH
, or
BOTH
.
7.
Type the
Key Lifetime
, and select the units;
Seconds
,
Minutes
, or
Hours
.
8.
Under
Perfect Forward Secrecy (PFS)
, select
None
,
Group 2
, or
Group 14
.
Note:
PFS is disabled by default. PFS allows faster IPSec setup, but is not very secure.
9.
Under
Hash
, select from the following:
SHA1
MD5
None
10.
If you selected
ESP
or
BOTH
for the
IPsec Security
type, select one or more of the following
Encryption
types:
Note:
Encryption
will not display if
IPsec Security
is set to
AH
.
AES
3DES
Null
11.
Click
Save
.
Editing or Deleting an Action
To edit or delete an action, select the action from the list, then click
Edit
or
Delete
.