Ipsec Parameters - AudioCodes Mediant 2000 User Manual

Voip media gateway
Hide thumbs Also See for Mediant 2000:
Table of Contents

Advertisement

45.4.6 IPSec Parameters

The Internet Protocol security (IPSec) parameters are described in the table below.
Parameter
IPSec Parameters
Web: Enable IP Security
EMS: IPSec Enable
[EnableIPSec]
Web: IKE Certificate Ext
Validate
[IKEcertificateExtValida
te]
IPSec Associations Table
Web: IP Security
Associations Table
EMS: IPSec SA Table
[IPSecSATable]
IPSec Proposal Table
Web: IP Security
Proposal Table
EMS: IPSec Proposal
Table
[IPSecProposalTable]
User's Manual
IPSec Parameters
Enables IPSec on the device.
[0] Disable (default)
[1] Enable
Note: For this parameter to take effect, a device reset is required.
Enables the validation of the extensions (keyUsage and
extentedKeyUsage) of peer certificates. This validation ensures that the
signing CA is authorized to sign certificates and that the end-entity
certificate is authorized to negotiate a secure IPSec connection.
[[0] Disable (default)
[1] Enable
This table parameter defines the IPSec SA table. This table allows you to
configure the Internet Key Exchange (IKE) and IP Security (IPSec)
protocols. You can define up to 20 IPSec peers.
The format of this parameter is as follows:
[ IPsecSATable ]
FORMAT IPsecSATable_Index =
IPsecSATable_RemoteEndpointAddressOrName,
IPsecSATable_AuthenticationMethod, IPsecSATable_SharedKey,
IPsecSATable_SourcePort, IPsecSATable_DestPort,
IPsecSATable_Protocol, IPsecSATable_Phase1SaLifetimeInSec,
IPsecSATable_Phase2SaLifetimeInSec,
IPsecSATable_Phase2SaLifetimeInKB, IPsecSATable_DPDmode,
IPsecSATable_IPsecMode, IPsecSATable_RemoteTunnelAddress,
IPsecSATable_RemoteSubnetIPAddress,
IPsecSATable_RemoteSubnetPrefixLength,
IPsecSATable_InterfaceName;
[ \IPsecSATable ]
For example:
IPsecSATable 1 = 0, 10.3.2.73, 0, 123456789, 0, 0, 0, 0, 28800, 3600, ;
In the above example, a single IPSec/IKE peer (10.3.2.73) is configured.
Pre-shared key authentication is selected, with the pre-shared key set to
123456789. In addition, a lifetime of 28800 seconds is selected for IKE
and a lifetime of 3600 seconds is selected for IPSec.
Note: For a detailed description of this table, see 'Configuring IP Security
Associations Table' on page 140.
This table parameter defines up to four IKE proposal settings, where
each proposal defines an encryption algorithm, an authentication
algorithm, and a Diffie-Hellman group identifier.
[ IPsecProposalTable ]
FORMAT IPsecProposalTable_Index =
IPsecProposalTable_EncryptionAlgorithm,
IPsecProposalTable_AuthenticationAlgorithm,
536
Description
Document #: LTRT-68822
Mediant 2000

Advertisement

Table of Contents
loading

Table of Contents