3Com 3032 Configuration Manual page 594

3com 3032: user guide
Hide thumbs Also See for 3032:
Table of Contents

Advertisement

590
C
41: C
HAPTER
ONFIGURING
Selecting an Encryption
Algorithm
Selecting an
Authentication
Algorithm
Configuring Pre-shared
Key
Selecting the Hashing
Algorithm
IKE
The system creates only the default IKE security policy that cannot be deleted or
modified by users.
The two types of encryption algorithms that are supported are the 56-bit
DES-Cipher Block Chaining (DES-CBC) algorithm and the 168-bit 3DES-CBC
algorithm. Before being encrypted, each plain text block performs exclusive-OR
operation with an encryption block, thus the same plain text block never maps the
same encryption and the security is enhanced.
Perform the following configurations in IKE proposal view.
Table 657 Select Encryption Algorithm
Operation
Select encryption algorithm
Set the encryption algorithm to the
default value
By default, DES-CBC encryption algorithm (i.e. parameter
Pre-share key is the only supported authentication algorithm.
Perform the following configurations in IKE proposal view.
Table 658 Select Authentication Method
Operation
Select authentication method
Restore the authentication method to the
default value
By default, pre share key (i.e.,
If pre-shared key authentication method is selected, it is necessary to configure
pre-shared key.
Perform the following configurations in system view.
Table 659 Configure Pre-shared Key
Operation
Configure pre-shared key
Delete pre-shared key to restore its default
value
By default, both ends of the security channel have no pre-shared keys.
Hashing algorithms use HMAC framework to achieve its function. HMAC
algorithm adopts an encryption hashing function to authenticate messages,
providing frameworks to insert various hashing algorithms, such as SHA-1 and
MD5.
Command
encryption-algorithm { des-cbc |
3des-cbc }
undo encryption-algorithm
Command
authentication-method pre-share
undo authentication-method pre-share
) algorithm is adopted.
pre-share
Command
ike pre-shared-key key remote
remote-address
undo ike pre-shared-key key remote
remote-address
is adopted.
des-cbc)

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

303430333035304030413036 ... Show all

Table of Contents