Canon VB-M42 Network Camera VB-H43/VB-H630VE/VB-H630D/VB-H730F/VB-M42/VB-M620V - Page 77

[IPsec] Setting IPsec, IPsec, Auto Key Exchange Settings, IPsec Set Auto Key Exchange

Page 77 highlights

[IPsec] Setting IPsec The following can be set here. • IPsec Set the IPsec setting method. • Auto Key Exchange Settings Set auto key exchange. • IPsec Set IP security can be specified through auto key exchange or manual setting with up to five communicating devices. IPsec (6) [DH Group] Select the key generation information for the DH algorithm that will be used for key exchange via auto 4 key exchange protocol IKE. The security level increases with higher group numbers. (7) [ISAKMP SA Validity Period (min)] Set the duration of validity for ISAKMP SA (factory default setting is [480]). Setting Page IPsec Set (Auto Key Exchange) IPsec Sets 1 to 5 are available, and you can specify IPsec settings for one communication device for each IPsec Set. (1) [IPsec] Key settings for use with IPsec can be selected as [Auto Key Exchange] or [Manual]. Auto Key Exchange Settings (1) [IPsec SA Encryption Algorithm] Set the IPsec SA encryption algorithm to [AES ->3DES], [AES->3DES->DES] or [AES->3DES->DES ->NULL]. The specified algorithm will be checked for an applicable encryption algorithm starting from the left. (2) [IPsec SA Authentication Algorithm] Set the IPsec SA authentication algorithm to [HMAC_SHA1_96] or [HMAC_SHA1_96-> HMAC_MD5_96]. The specified algorithm will be checked for an applicable authentication algorithm starting from the left. (3) [IPsec SA Validity Period (min)] Set the duration of validity for IPsec SA (factory default setting is [480]). (4) [ISAKMP SA Encryption Algorithm] Set the SA encryption algorithm for use with auto key exchange protocol IKE to [AES->3DES] or [AES-> 3DES->DES]. (5) [ISAKMP SA Authentication Algorithm] Set the SA authentication algorithm for use with auto key exchange protocol IKE to [SHA1] or [SHA1 ->MD5]. (1) [IPsec Set] Set IPsec Set to [Disable], [Enable in IPv4] or [Enable in IPv6]. (2) [IPsec Mode] Set IPsec mode to [Tunnel Mode] or [Transport Mode]. (3) [Destination IPv4 Address], [Destination IPv6 Address] Enter the IP address of the connection destination. (4) [Source IPv4 Address], [Source IPv6 Address] Enter the IP address of the source. (5) [Security Protocol] Set the IPsec protocol to [ESP], [AH] or [ESP and AH]. If [ESP] is selected, enter only the setting items relating to ESP. If [AH] is selected, enter only the setting items relating to AH. If [ESP and AH] is selected, enter all setting items. (6) [Security Gateway IPv4 Address], [Security Gateway IPv6 Address] If IPsec mode is set to [Tunnel Mode] in (2), set the IP address of the security gateway. (7) [Destination Subnet Mask Length] (IPv4), [Destination Prefix Length] (IPv6) This setting is required only if IPsec mode is set to [Tunnel Mode] in (2). If IPv6 is used, enter a desired prefix length for the connection destination in the range of 16 to 128. If IPv4 is used, enter a desired length in the range of 1 to 32. 77

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195

77
4
S
etting Page
IPsec
(1) [IPsec]
Key settings for use with IPsec can be selected as
[Auto Key Exchange] or [Manual].
Auto Key Exchange Settings
(1) [IPsec
S
A Encryption Algorithm]
Set the IPsec SA encryption algorithm to [AES
->3DES], [AES->3DES->DES] or [AES->3DES->DES
->NULL].
The specified algorithm will be checked for an
applicable encryption algorithm starting from the left.
(2) [IPsec
S
A Authentication Algorithm]
Set the IPsec SA authentication algorithm to
[HMAC_SHA1_96] or [HMAC_SHA1_96->
HMAC_MD5_96].
The specified algorithm will be checked for an
applicable authentication algorithm starting from the
left.
(3) [IPsec
S
A Validity Period (min)]
Set the duration of validity for IPsec SA (factory default
setting is [480]).
(4) [I
S
AKMP
S
A Encryption Algorithm]
Set the SA encryption algorithm for use with auto key
exchange protocol IKE to [AES->3DES] or [AES->
3DES->DES].
(5) [I
S
AKMP
S
A Authentication Algorithm]
Set the SA authentication algorithm for use with auto
key exchange protocol IKE to [SHA1] or [SHA1
->MD5].
(6)
[DH Group]
Select the key generation information for the DH
algorithm that will be used for key exchange via auto
key exchange protocol IKE. The security level
increases with higher group numbers.
(7) [I
S
AKMP
S
A Validity Period (min)]
Set the duration of validity for ISAKMP SA (factory
default setting is [480]).
IPsec Set (Auto Key Exchange)
IPsec Sets 1 to 5 are available, and you can specify IPsec
settings for one communication device for each IPsec Set.
(1) [IPsec
S
et]
Set IPsec Set to [Disable], [Enable in IPv4] or [Enable
in IPv6].
(2)
[IPsec Mode]
Set IPsec mode to [Tunnel Mode] or [Transport
Mode].
(3)
[Destination IPv4 Address], [Destination IPv6 Address]
Enter the IP address of the connection destination.
(4) [
S
ource IPv4 Address], [
S
ource IPv6 Address]
Enter the IP address of the source.
(5) [
S
ecurity Protocol]
Set the IPsec protocol to [ESP], [AH] or [ESP and AH].
If [ESP] is selected, enter only the setting items
relating to ESP.
If [AH] is selected, enter only the setting items relating
to AH.
If [ESP and AH] is selected, enter all setting items.
(6) [
S
ecurity Gateway IPv4 Address], [
S
ecurity Gateway
IPv6 Address]
If IPsec mode is set to [Tunnel Mode] in (2), set the IP
address of the security gateway.
(7) [Destination
S
ubnet Mask Length] (IPv4), [Destination
Prefix Length] (IPv6)
This setting is required only if IPsec mode is set to
[Tunnel Mode] in (2).
If IPv6 is used, enter a desired prefix length for the
connection destination in the range of 16 to 128.
If IPv4 is used, enter a desired length in the range of 1
to 32.
[IPsec] Setting IPsec
The following can be set here.
IPsec
Set the IPsec setting method.
Auto Key Exchange
S
ettings
Set auto key exchange.
IPsec
S
et
IP security can be specified through auto key
exchange or manual setting with up to five
communicating devices.