Ipsec New Policy; Preconfigured Settings - Colubris Networks CN3000 Administrator's Manual

Table of Contents

Advertisement

Chapter 11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -Configuration parameters - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 11

IPSec new policy

Open the Security > IPSec page and click a policy in the list, or click Add New
Policy.
Preconfigured
The Internet Key Exchange protocol is used to negotiate IPSec security associations.
The negotiation is controlled by setting a number of different IKE options. To simplify the
settings
configuration of IPSec, the CN3000 presets some of these options, while others are
automatically defined based on the needs of the peer.
The following is a summary of the most important non-configurable IKE options:
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 259 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Hash algorithm
Phase 2 encryption algorithm
Oakley group or
Diffie-Hellman
Accepts the algorithm proposed by the
peer. Supports MD5 and SHA-1.
3DES
Accepts the group proposed by the peer.
Supports groups 2 and 5.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents