Configuring An Ike Peer - HP 6600 Security Configuration Manual

Table of Contents

Advertisement

In FIPS mode, both the IPsec SAs and the corresponding IKE SAs are renegotiated.
In non-FIPS mode, only the IPsec SAs are renegotiated.
To configure an IKE proposal:
Step
1.
Enter system view.
2.
Create an IKE proposal
and enter its view.
3.
Specify an encryption
algorithm for the IKE
proposal.
Specify an authentication
4.
method for the IKE
proposal.
5.
Specify an authentication
algorithm for the IKE
proposal.
6.
Specify a DH group for key
negotiation in phase 1.
7.
Set the ISAKMP SA lifetime
for the IKE proposal.

Configuring an IKE peer

For an IPsec policy that uses IKE, you must configure an IKE peer by performing the following tasks:
Specify the IKE negotiation mode for the local end to use in IKE negotiation phase 1. If the IP
address of the remote end is obtained dynamically and pre-shared key authentication is used, HP
recommends setting the IKE negotiation mode of the local end to aggressive. When acting as the
IKE negotiation responder, the local end uses the IKE negotiation mode of the remote end.
Command
system-view
ike proposal proposal-number
encryption-algorithm { 3des-cbc |
aes-cbc [ key-length ] | des-cbc }
authentication-method
{ pre-share | rsa-signature }
authentication-algorithm { md5 |
sha }
dh { group1 | group2 | group5 |
group14 }
sa duration seconds
298
Remarks
N/A
N/A
Optional.
In FIPS mode, DES-CBC or 3DES-CBC
are not supported, and the IKE
proposal uses 128-bit AES-CBC for
encryption by default.
In non-FIPS mode, the IKE proposal
uses 56-bit DES-CBC for encryption by
default.
Optional.
Pre-shared key by default.
Optional.
SHA1 by default.
In FIPS mode, MD5 is not supported.
Optional.
In FIPS mode, the default group is
group2, the 1024-bit Diffie-Hellman
group.
In non-FIPS mode, the default group is
group1, the 768-bit Diffie-Hellman
group.
Optional.
86400 seconds by default.
Before an ISAKMP SA expires, IKE
negotiates a new SA to replace it. DH
calculation in IKE negotiation takes
time, especially on low-end devices. To
prevent SA updates from influencing
normal communication, set the lifetime
greater than 10 minutes.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hsr6600

Table of Contents