Canon i-SENSYS MF729Cx Important Safety Instructions And Installation Manual page 461

Hide thumbs Also See for i-SENSYS MF729Cx:
Table of Contents

Advertisement

1
Certificate].
2
Click [Register Default Key] on the right of a key pair you want to use.
Viewing details of a key pair or certificate
You can check the details of the certificate or verify the certificate by clicking the corresponding text link under [Key
Name], or the certificate icon.
3
Specify the [Valid for] and [Authentication]/[Encryption]/[DH Group] settings.
10
Specify the IPSec Network Settings.
[Use PFS]
Select the check box to enable Perfect Forward Secrecy (PFS) for IPSec session keys. Enabling PFS enhances the security while
increasing the load on the communication. Make sure that PFS is also enabled for the other devices.
[Specify by Time]/[Specify by Size]
Set the conditions for terminating a session for IPSec SA. IPSec SA is used as a communication tunnel. Select either or both of the
check boxes as necessary. If both check boxes are selected, the IPSec SA session is terminated when either of the conditions has
been satisfied.
[Specify by
Time]
[Specify by
Size]
[Select Algorithm]
Select the [ESP], [ESP (AES-GCM)], or [AH (SHA1)] check box(es) depending on the IPSec header and the algorithm used. AES-
GCM is an algorithm for both authentication and encryption. If [ESP] is selected, also select algorithms for authentication and
encryption from the [ESP Authentication] and [ESP Encryption] drop-down lists.
[ESP
Authentication]
[ESP
Encryption]
[Connection Mode]
The connection mode of IPSec is displayed. The machine supports transport mode, in which the payloads of IP packets are
encrypted. Tunnel mode, in which whole IP packets (headers and payloads) are encapsulated is not available.
11
Click [OK].
If you need to register an additional security policy, return to step 6.
Verifying Key Pairs and Digital Certificates
Enter a time in minutes to specify how long a session lasts.
Enter a size in megabytes to specify how much data can be transported in a session.
To enable the ESP authentication, select [SHA1] for the hash algorithm. Select [Do Not Use] if you want
to disable the ESP authentication.
Select the encryption algorithm for ESP. You can select [NULL] if you do not want to specify the
algorithm, or select [Do Not Use] if you want to disable the ESP encryption.

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents