Avaya Business Secure Router 252 Configuration - Basics Instrukcja Użytkownika Strona 239

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 238
Chapter 13 VPN 239
Nortel Business Secure Router 252 Configuration — Basics
Figure 74 Two phases to set up the IPSec SA
In Phase 1 you must:
Choose a negotiation mode.
Authenticate the connection by entering a preshared key.
Choose an encryption algorithm.
Choose an authentication algorithm.
Choose a Diffie-Hellman public-key cryptography key group (DH1, DH2,
and DH5).
Set the IKE SA lifetime. In this field you can determine how long an IKE SA
will stay up before it times out. An IKE SA times out when the IKE SA
lifetime period expires. If an IKE SA times out when an IPSec SA is already
established, the IPSec SA stays connected.
In Phase 2 you must:
Choose which protocol to use (ESP or AH) for the IKE key exchange.
Choose an encryption algorithm.
Choose an authentication algorithm
Choose whether to enable Perfect Forward Secrecy (PFS) using
Diffie-Hellman public-key cryptography–see “Perfect Forward Secrecy
(PFS)” on page 241. Select None (the default) to disable PFS.
Choose Tunnel mode or Transport mode.
Przeglądanie stron 238
1 2 ... 234 235 236 237 238 239 240 241 242 243 244 ... 459 460

Komentarze do niniejszej Instrukcji

Brak uwag