Ikev2 Client Setup - D-Link NetDefendOS User Manual

Network security firewall
Hide thumbs Also See for NetDefendOS:
Table of Contents

Advertisement

NetDefendOS supports IPsec using both the IKEv1 and IKEv2 protocols. This section describes the
specific considerations that are needed when IKEv2 is used.
The IKE Version Property
The IKE Version property of an IPsec Tunnel object determines the IKE version used when the
tunnel is set up. This property can have one of the following values:
IKEv1 - NetDefendOS will use IKEv1 for tunnel setup. This is the default value.
IKEv2 - NetDefendOS will use IKEv2 for tunnel setup.
Auto - NetDefendOS will first attempt to use IKEv2 for tunnel setup and revert back to IKEv1 if
unsuccessful.
Configuring IKEv2 based IPsec tunnels is almost exactly the same as for IKEv1 but the following
differences should be noted:
IKE Mode can only be used with IKEv1 tunnels.
Authentication using XAuth is only possible with IKEv1. Authentication with IKEv2 must use
EAP.
The AES-XCBC authentication algorithm is supported by IKEv2 only. If AES-XCBC is used in a
proposal list with IKEv1, it will be skipped. If AES-XCBC is the only algorithm in the proposal
list with IKEv1, tunnel setup will fail.
The Encapsulation Mode property of an IKEv2 tunnel can only be set to Tunnel. This means
that IKEv2 should not be used with L2TP (see Section 9.5.2, "L2TP Servers").
EAP Authentication Settings
Authentication with IKEv2 is done using EAP. The following IPsec Tunnel object properties are
used with IKv2 EAP:
Require EAP for Inbound Tunnels
This property is disabled by default. It must be enabled if clients which initiate a connection
will be authenticated using EAP.
Request EAP ID
This property is enabled by default and allows different EAP credentials to be used during the
IKE and IPsec phases of the tunnel. This should always be enabled when the inbuilt Microsoft
WIndows IPsec client connects. The administrator may disable this property for other types of
clients.
Global Advanced Settings for IKEv2
All the global settings that are specific to IKEv2 are listed under the IKEv2 header in Section 9.4.9,
"IPsec Advanced Settings".

9.4.5. IKEv2 Client Setup

This section goes though the steps needed for setting up NetDefendOS to communicate with
714
Chapter 9: VPN

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents