Dell PowerConnect W-Airwave W-Airwave 7.2 Configuration Guide - Page 130

VPN Dialers, Add New VPN Dialer, The new profile appears below

Page 130 highlights

Table 58 Security > User Roles > Add VPN Dialer Field Descriptions (Continued) Field Default Description IKE Lifetime (300-85400 secs) 28800 Specify the Internet Key Exchange (IKE) Lifetime in seconds. When this period of time expires, the IKE SA is replaced by a new SA or is terminated. The IKE SA specifies values for the IKE exchange: the authentication method used, the encryption and hash algorithms, the Diffie-Hellman group used, the lifetime of the IKE SA in seconds, and the shared secret key values for the encryption algorithms. The IKE SA in each peer is bi-directional. IKE Encryption 168-bit 3DESCBC Select the Internet Key Exchange (IKE) encryption method from the following two options:  168-bit 3DES-CBC  56-bit DES-CBC IKE Diffie-Hellman Group 1024-bit (1) Select the IPSEC Mode Group that matches the Diffie Hellman Group configured for the IPSEC policy. The two options are as follows:  1024-bit  768-bit The IKE policy selections, along with the preshared key, need to be reflected in the VPN configuration. Set the VPN configuration on clients to match the choices made above. In case the Dell PowerConnect W dialer is used, these configuration need to be made on the dialer prior to downloading the dialer onto the local client. IKE Hash Algorithm SHA Set the IKE Hash Algorithm to either SHA or MD5, to match the IKE policy for IPSEC. IKE Authentication Pre-Shared IKE Phase 1 authentication can be done with either an IKE preshared key or digital certificates. This establishes how the client is authenticated with the internal database on the controller. The options are Pre-Shared Keys or RSA Signatures. IPSEC Lifetime 7200 Define the IPSEC lifetime in seconds, after which a new IPSEC key is required. IPSEC Diffie Hellman 1024-bit (1) Group Select the IPSEC Mode Group that matches the Diffie Hellman Group configured for the IKE policy. The two options are as follows:  1024-bit  768-bit The IPSEC policy selections, along with the preshared key, need to be reflected in the VPN configuration. Set the VPN configuration on clients to match the choices made above. In case the Dell PowerConnect W dialer is used, these configuration need to be made on the dialer prior to downloading the dialer onto the local client. IPSEC Encryption 168-bit 3DES Specify the type of IPSEC encryption to support for the VPN. Options are as follows:  Encapsulating Security Payload (ESP) with 168-bit 3DES  ESP with 56-bit DES IPSEC Hash Algorithm SHA Set the IKE Hash Algorithm to either SHA or MD5, to match the IKE policy for IKE Hash Algorithm. Select Add to finish the new VPN Dialers profile, or click Save to complete the editing of an existing profile. You return to the VPN Dialers page. The new profile appears below the Add New VPN Dialer button. 130 | Dell PowerConnect W Configuration Reference Dell PowerConnect W AirWave 7.2 | Configuration Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160

130
|
Dell PowerConnect W Configuration Reference
Dell PowerConnect W AirWave 7.2
| Configuration Guide
Select
Add
to finish the new
VPN Dialers
profile, or click
Save
to complete the editing of an existing profile. You
return to the
VPN Dialers
page. The new profile appears below the
Add New VPN Dialer
button.
IKE Lifetime
(300-85400 secs)
28800
Specify the Internet Key Exchange (IKE) Lifetime in seconds. When this period of time
expires, the IKE SA is replaced by a new SA or is terminated.
The IKE SA specifies values for the IKE exchange: the authentication method used,
the encryption and hash algorithms, the Diffie-Hellman group used, the lifetime of the
IKE SA in seconds, and the shared secret key values for the encryption algorithms.
The IKE SA in each peer is bi-directional.
IKE Encryption
168-bit 3DES-
CBC
Select the Internet Key Exchange (IKE) encryption method from the following two
options:
168-bit 3DES-CBC
56-bit DES-CBC
IKE Diffie-Hellman
Group
1024-bit (1)
Select the IPSEC Mode Group that matches the Diffie Hellman Group configured for
the IPSEC policy. The two options are as follows:
1024-bit
768-bit
The IKE policy selections, along with the preshared key, need to be reflected in the
VPN configuration. Set the VPN configuration on clients to match the choices made
above. In case the Dell PowerConnect W dialer is used, these configuration need to
be made on the dialer prior to downloading the dialer onto the local client.
IKE Hash Algorithm
SHA
Set the IKE Hash Algorithm to either SHA or MD5, to match the IKE policy for IPSEC.
IKE Authentication
Pre-Shared
IKE Phase 1 authentication can be done with either an IKE preshared key or digital
certificates. This establishes how the client is authenticated with the internal
database on the controller.
The options are
Pre-Shared Keys
or
RSA Signatures
.
IPSEC Lifetime
7200
Define the IPSEC lifetime in seconds, after which a new IPSEC key is required.
IPSEC Diffie Hellman
Group
1024-bit (1)
Select the IPSEC Mode Group that matches the Diffie Hellman Group configured for
the IKE policy. The two options are as follows:
1024-bit
768-bit
The IPSEC policy selections, along with the preshared key, need to be reflected in the
VPN configuration. Set the VPN configuration on clients to match the choices made
above. In case the Dell PowerConnect W dialer is used, these configuration need to
be made on the dialer prior to downloading the dialer onto the local client.
IPSEC Encryption
168-bit 3DES
Specify the type of IPSEC encryption to support for the VPN. Options are as follows:
Encapsulating Security Payload (ESP) with 168-bit 3DES
ESP with 56-bit DES
IPSEC Hash Algorithm
SHA
Set the IKE Hash Algorithm to either SHA or MD5, to match the IKE policy for IKE Hash
Algorithm.
Table 58
Security > User Roles > Add VPN Dialer Field Descriptions
(Continued)
Field
Default
Description