Panasonic BB-HGW700A Operating Instructions Manual page 90

Network camera management system
Hide thumbs Also See for BB-HGW700A:
Table of Contents

Advertisement

Operating Instructions
Phase 1 Setup
Conversion Mode
Life Time
Proposal Entry
Proposal Encryption
Proposal Hash
Proposal DH Group
Phase 2 Setup
Life Time
PFS
Proposal Entry
Proposal Encryption
Proposal Hash
Notes
When the conversion mode is set to Aggressive, both IPsec devices must have the same DH group
set.
When connecting an IPsec camera to the WAN side, the conversion mode must be set to Main.
90
Set the IKE phase 1 conversion mode to Main or Aggressive. The
key conversion procedure for Aggressive is simpler but security is
slightly reduced.
Set the IKE SA lifetime. The time must be set between 5 minutes and
2400 hours.
Set whether to Enable or Disable this proposal. Proposals that are
disabled will not be proposed.
Set the method of encryption used in phase 1. Select an encryption
method from DES, 3DES, AES (128 bit), AES (192 bit), and AES
(256 bit).
Set the authentication algorithm (hash). Select from MD5 and SHA-
1.
Set the DH (Diffie-Hellman) group used in phase 1. Select between 1
and 2. DH group 2 is has increased security compared to DH group
1, but group 1 is not weak.
Set the IPsec SA lifetime. The time must be set between 5 minutes
and 2400 hours.
Set whether to turn on PFS (Perfect Forward Security) in phase 2.
Select from Enable DH Group 2, Enable DH Group 1, and Disable.
When Enable Group 2 is selected, the Diffie-Hellman exchange is re-
performed in phase 2, and DH Group 2 creates a secret shared key.
When Enable Group 1 is selected, the Diffie-Hellman exchange is re-
performed in phase 2, and DH Group 1 creates a secret shared key.
When Disabled is selected, the secret shared key created in phase 1
is used in phase 2. Security is increased when PFS is enabled rather
than disabled.
Set whether to Enable or Disable this proposal. Proposals that have
Disable set will not be proposed.
Set the method of encryption. Select from an encryption method
from DES, 3DES, AES (128 bit), AES (192 bit), AES (256 bit) and
NULL.
Set the authentication algorithm (hash). Select from MD5, SHA-1,
and None (authentication algorithm not used).

Advertisement

Table of Contents
loading

Table of Contents