Brocade Communications Systems RFS6000 System Reference Manual page 408

Provides centralized wireless lan (wlan)
Hide thumbs Also See for RFS6000:
Table of Contents

Advertisement

6
A IKE policy matches when they have the same encryption, hash, authentication and Diffie-Hellman
settings. The SA lifetime must also be less than or equal to the lifetime in the policy sent. If the
lifetimes do not match, the shorter lifetime applies. If no match exists, IKE refuses negotiation.
To view the current set of IKE policies:
1. Select Security > IKE Settings from the main menu tree.
2. Click the IKE Policies tab.
3. Refer to the values displayed within the IKE Policies tab to determine if an existing policy
Sequence Number
Displays the sequence number for the IKE policy. The available range is from 1 to 10,000, with 1 being the highest
priority value.
Encryption
Displays the encryption method protecting data transmitted between peers. Options include:
DES 56-bit DES-CBC. The default value.
3DES - 168-bit Triple DES.
AES - 128-bit AES.
AES 192 - 192-bit AES.
AES 256 - 256-bit AES.
Hash Value
Displays the hash algorithm used to ensure data integrity. The hash value validates a packet comes from its
intended destination, and has not been modified in transit. Options include:
SHA - The default value.
MD5 - MD5 has a smaller digest and is somewhat faster than SHA-1.
Authentication Type
Displays the authentication scheme used to validate the identity of each peer. Pre-shared keys do not scale
accurately with a growing network but are easier to maintain in a small network. Options include:
Pre-shared Key - Uses pre-shared keys.
RSA Signature - Uses a digital certificate with keys generated by the RSA signatures algorithm.
SA Lifetime
Displays an integer for the SA lifetime. With longer lifetimes, security defines future IPSec security associations
quickly. Encryption strength is great enough to ensure security without using fast rekey times. Brocade recommends
using the default value.
DH Group
Displays the Diffie-Hellman (DH) group identifier. IPSec peers use the defined value to derive a shared secret
without transmitting it to one another.
396
requires revision, removal or a new policy requires creation.
Brocade Mobility RFS4000, RFS6000, and RFS7000 System Reference Guide
53-1002515-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Rfs4000Rfs7000

Table of Contents