3Com VCX v7111 User Manual page 328

Voip
Hide thumbs Also See for VCX v7111:
Table of Contents

Advertisement

SPD Table Configuration Parameters
Table 94
Parameter Name
Remote IP Address
[IPSecPolicyRemoteIPAddress]
Local IP Address Type
[IPSecPolicyLocalIPAddressType]
Source Port
[IPSecPolicySrcPort]
Destination Port
[IPSecPolicyDstPort]
Protocol
[IPSecPolicyProtocol]
Related Key Exchange Method Index
[IPsecPolicyKeyExchangeMethodIndex]
IKE Second Phase Parameters (Quick Mode)
SA Lifetime (sec)
I[PsecPolicyLifeInSec]
SA Lifetime (KB)
[IPSecPolicyLifeInKB]
The lifetime parameters (IPsecPolicyLifeInSec and IPSecPolicyLifeInKB) determine the duration an SA is
valid. When the lifetime of the SA expires, it is automatically renewed by performing the IKE second phase
negotiations. To refrain from a situation where the SA expires, a new SA is being negotiated while the old
one is still valid. As soon as the new SA is created, it replaces the old one. This procedure occurs whenever
an SA is about to expire.
328
Description
Defines the destination IP address (or a
FQDN) the IPSec mechanism is applied to.
This parameter is mandatory.
When a FQDN is used, a DNS
server must be configured
(DNSPriServerIP).
Determines the local interface to which the
encryption is applied (applicable to multiple
IPs and VLANs).
0 = OAM interface (default).
1 = Control interface.
Defines the source port the IPSec
mechanism is applied to.
The default value is 0 (any port).
Defines the destination port the IPSec
mechanism is applied to.
The default value is 0 (any port).
Defines the protocol type the IPSec
mechanism is applied to.
0
= Any protocol (default).
17
= UDP.
6
= TCP.
Or any other protocol type defined by IANA
(Internet Assigned Numbers Authority).
Determines the index for the corresponding IKE entry. Note that
several policies can be associated with a single IKE entry.
The valid range is 0 to 19. The default value is 0.
Determines the time (in seconds) the SA negotiated in the
second IKE session (quick mode) is valid. After the time expires,
the SA is re-negotiated.
The default value is 28800 (8 hours).
Determines the lifetime (in kilobytes) the SA negotiated in the
second IKE session (quick mode) is valid. After this size is
reached, the SA is re-negotiated.
The default value is 0 (this parameter is ignored).
®
3Com
VCX V7111 VoIP Gateway User Guide
IPSec is applied to
outgoing packets
whose IP address,
destination port,
source port and
protocol type
match the values
defined for these
four parameters.

Advertisement

Table of Contents
loading

Table of Contents