Figure 74 Two Phases To Set Up The Ipsec Sa - Nortel BSR252 Configuration - Basics

Business secure router
Hide thumbs Also See for BSR252:
Table of Contents

Advertisement

Figure 74 Two phases to set up the IPSec SA

In Phase 1 you must:
Choose a negotiation mode.
Authenticate the connection by entering a preshared key.
Choose an encryption algorithm.
Choose an authentication algorithm.
Choose a Diffie-Hellman public-key cryptography key group (DH1, DH2,
and DH5).
Set the IKE SA lifetime. In this field you can determine how long an IKE SA
will stay up before it times out. An IKE SA times out when the IKE SA
lifetime period expires. If an IKE SA times out when an IPSec SA is already
established, the IPSec SA stays connected.
In Phase 2 you must:
Choose which protocol to use (ESP or AH) for the IKE key exchange.
Choose an encryption algorithm.
Choose an authentication algorithm
Choose whether to enable Perfect Forward Secrecy (PFS) using
Diffie-Hellman public-key cryptography–see
(PFS)" on page
241. Select None (the default) to disable PFS.
Choose Tunnel mode or Transport mode.
Nortel Business Secure Router 252 Configuration — Basics
Chapter 13 VPN 239
"Perfect Forward Secrecy

Advertisement

Table of Contents
loading

Table of Contents