Canon VB-S800D User Manual - Page 62

[IPsec] Setting IPsec, IPsec, Auto Key Exchange Settings, IPsec Set Auto Key Exchange

Page 62 highlights

[IPsec] Setting IPsec The following can be set here. • IPsec Set the IPsec setting method. • Auto Key Exchange Settings Set auto key exchange. • IPsec Set IP security can be specified through auto key exchange or manual setting with up to five communicating devices. IPsec (6) [DH Group] Select [Group 2] or [Group 2->Group 1] for the key generation information that will be used in the DH algorithm for key exchange via auto key exchange protocol IKE. (7) [ISAKMP SA Validity Period (min)] Set the duration of validity for ISAKMP SA (factory default setting is [480]). IPsec Set (Auto Key Exchange) IPsec Sets 1 to 5 are available, and you can specify IPsec settings for one communication device for each IPsec Set. (1) [IPsec] Key settings for use with IPsec can be selected as [Auto Key Exchange] or [Manual]. Auto Key Exchange Settings (1) [IPsec SA Encryption Algorithm] Set the IPsec SA encryption algorithm to [AES>3DES], [AES->3DES->DES] or [AES->3DES->DES>NULL]. The specified algorithm will be checked for an applicable encryption algorithm starting from the left. (2) [IPsec SA Authentication Algorithm] Set the IPsec SA authentication algorithm to [HMAC_SHA1_96] or [HMAC_SHA1_96-> HMAC_MD5_96]. The specified algorithm will be checked for an applicable authentication algorithm starting from the left. (3) [IPsec SA Validity Period (min)] Set the duration of validity for IPsec SA (factory default setting is [480]). (4) [ISAKMP SA Encryption Algorithm] Set the SA encryption algorithm for use with auto key exchange protocol IKE to [AES->3DES] or [AES-> 3DES->DES]. (5) [ISAKMP SA Authentication Algorithm] Set the SA authentication algorithm for use with auto key exchange protocol IKE to [SHA1] or [SHA1>MD5]. (1) [IPsec Set] Set IPsec Set to [Disable], [Enable in IPv4] or [Enable in IPv6]. (2) [IPsec Mode] Set IPsec mode to [Tunnel Mode] or [Transport Mode]. (3) [Destination IPv4 Address], [Destination IPv6 Address] Enter the IP address of the connection destination. (4) [Source IPv4 Address], [Source IPv6 Address] Enter the IP address of the source. (5) [Security Protocol] Set the IPsec protocol to [ESP], [AH] or [ESP and AH]. If [ESP] is selected, enter only the setting items relating to ESP. If [AH] is selected, enter only the setting items relating to AH. If [ESP and AH] is selected, enter all setting items. (6) [Security Gateway IPv4 Address], [Security Gateway IPv6 Address] If IPsec mode is set to [Tunnel Mode] in (2), set the IP address of the security gateway. (7) [Destination Subnet Mask Length] (IPv4), [Destination Prefix Length] (IPv6) This setting is required only if IPsec mode is set to [Tunnel Mode] in (2). If IPv6 is used, enter a desired prefix length for the connection destination in the range of 16 to 128. If IPv4 is used, enter a desired length in the range of 1 to 32. 62

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176

62
IPsec
(1) [IPsec]
Key settings for use with IPsec can be selected as
[Auto Key Exchange] or [Manual].
Auto Key Exchange Settings
(1) [IPsec
S
A Encryption Algorithm]
Set the IPsec SA encryption algorithm to [AES-
>3DES], [AES->3DES->DES] or [AES->3DES->DES-
>NULL].
The specified algorithm will be checked for an
applicable encryption algorithm starting from the left.
(2) [IPsec
S
A Authentication Algorithm]
Set the IPsec SA authentication algorithm to
[HMAC_SHA1_96] or [HMAC_SHA1_96->
HMAC_MD5_96].
The specified algorithm will be checked for an
applicable authentication algorithm starting from the
left.
(3) [IPsec
S
A Validity Period (min)]
Set the duration of validity for IPsec SA (factory default
setting is [480]).
(4) [I
S
AKMP
S
A Encryption Algorithm]
Set the SA encryption algorithm for use with auto key
exchange protocol IKE to [AES->3DES] or [AES->
3DES->DES].
(5) [I
S
AKMP
S
A Authentication Algorithm]
Set the SA authentication algorithm for use with auto
key exchange protocol IKE to [SHA1] or [SHA1-
>MD5].
(6)
[DH Group]
Select [Group 2] or [Group 2->Group 1] for the key
generation information that will be used in the DH
algorithm for key exchange via auto key exchange
protocol IKE.
(7) [I
S
AKMP
S
A Validity Period (min)]
Set the duration of validity for ISAKMP SA (factory
default setting is [480]).
IPsec Set (Auto Key Exchange)
IPsec Sets 1 to 5 are available, and you can specify IPsec
settings for one communication device for each IPsec Set.
(1) [IPsec
S
et]
Set IPsec Set to [Disable], [Enable in IPv4] or [Enable
in IPv6].
(2)
[IPsec Mode]
Set IPsec mode to [Tunnel Mode] or [Transport
Mode].
(3)
[Destination IPv4 Address], [Destination IPv6 Address]
Enter the IP address of the connection destination.
(4) [
S
ource IPv4 Address], [
S
ource IPv6 Address]
Enter the IP address of the source.
(5) [
S
ecurity Protocol]
Set the IPsec protocol to [ESP], [AH] or [ESP and AH].
If [ESP] is selected, enter only the setting items
relating to ESP.
If [AH] is selected, enter only the setting items relating
to AH.
If [ESP and AH] is selected, enter all setting items.
(6) [
S
ecurity Gateway IPv4 Address], [
S
ecurity Gateway
IPv6 Address]
If IPsec mode is set to [Tunnel Mode] in (2), set the IP
address of the security gateway.
(7) [Destination
S
ubnet Mask Length] (IPv4), [Destination
Prefix Length] (IPv6)
This setting is required only if IPsec mode is set to
[Tunnel Mode] in (2).
If IPv6 is used, enter a desired prefix length for the
connection destination in the range of 16 to 128.
If IPv4 is used, enter a desired length in the range of 1
to 32.
[IPsec] Setting IPsec
The following can be set here.
IPsec
Set the IPsec setting method.
Auto Key Exchange
S
ettings
Set auto key exchange.
IPsec
S
et
IP security can be specified through auto key
exchange or manual setting with up to five
communicating devices.