3Com VCX v7111 User Manual page 324

Voip
Hide thumbs Also See for VCX v7111:
Table of Contents

Advertisement

IKE Table Configuration Parameters
Table 92
Parameter Name
Shared Key
[IKEPolicySharedKey]
First to Fourth Proposal Encryption
Type
[IKEPolicyProposalEncryption_X]
First to Fourth Proposal Authentication
Type
[IKEPolicyProposalAuthentication_X]
First to Fourth Proposal DH Group
[IKEPolicyProposalDHGroup_X]
Authentication Method
[IkePolicyAuthenticationMethod]
324
Description
Determines the pre-shared key (in textual format).
Both peers must register the same pre-shared key for the
authentication process to succeed.
The pre-shared key forms the basis of IPSec security and
should therefore be handled cautiously (in the same way
as sensitive passwords). It is not recommended to use the
same pre-shared key for several connections.
Since the ini file is in plain text format, loading it to the
gateway over a secure network connection is
recommended, preferably over a direct crossed-cable
connection from a management PC. For added
confidentiality, use the encoded ini file option (described in
Secured ini
File).
After it is configured, the value of the pre-shared key
cannot be obtained using Web, ini file or SNMP (see
and IKE Configuration Tables
Determines the encryption type used in the main mode negotiation
for up to four proposals.
X stands for the proposal number (0 to 3).
The valid encryption values are:
Not Defined (default)
DES-CBC
[1]
Triple DES-CBC [2]
AES
[3]
Determines the authentication protocol used in the main mode
negotiation for up to four proposals.
X stands for the proposal number (0 to 3).
The valid authentication values are:
Not Defined (default)
HMAC-SHA1-96) [2]
HMAC-MD5-96
[4]
Determines the length of the key created by the DH protocol for up
to four proposals.
X stands for the proposal number (0 to 3).
The valid DH Group values are:
Not Defined (default)
DH-786-Bit
[0]
DH-1024-Bit
[1]
Determines the authentication method for IKE.
The valid authentication method values include:
0 = Pre-shared Key (default)
1 = RSA Signature
For pre-shared key based authentication, peers
participating in an IKE exchange must have a prior (out-of-
band) knowledge of the common key (see
IKEPolicySharedKey parameter).
For RSA signature based authentication, peers must be
loaded with a certificate signed by a common CA. For
additional information on certificates, see
Replacement.
®
3Com
Confidentiality).
VCX V7111 VoIP Gateway User Guide
IPSec
Server Certificate

Advertisement

Table of Contents
loading

Table of Contents