Ipsec Parameters; Authentication Algorithm; Encryption Algorithm; Encapsulation Mode - Cisco VPN 3000 User Manual

Table of Contents

Advertisement

13
Policy Management

IPSec Parameters

These parameters apply to IPSec SAs, which are Phase 2 SAs negotiated under IPSec, where the two
parties establish conditions for use of the tunnel.

Authentication Algorithm

This parameter specifies the data, or packet, authentication algorithm. Packet authentication proves that
data comes from whom you think it comes from; it is often referred to as "data integrity" in VPN
literature. The IPSec ESP (Encapsulating Security Payload) protocol provides both encryption and
authentication.
Click the drop-down menu button and select the algorithm:
None
ESP/MD5/HMAC-128
MD5 hash function using a 128-bit key. This is the default selection.
ESP/SHA/HMAC-160
This selection is more secure but requires more processing overhead.

Encryption Algorithm

This parameter specifies the data, or packet, encryption algorithm. Data encryption makes the data
unreadable if intercepted.
Click the drop-down menu button and select the algorithm:
Null
DES-56
3DES-168
most secure.

Encapsulation Mode

This parameter specifies the mode for applying ESP encryption and authentication; in other words, what
part of the original IP packet has ESP applied.
Click the drop-down menu button and select the mode:
Tunnel
data), thus hiding the ultimate source and destination addresses. This is the default selection, and it
is the most secure.
Transport
of the original IP packet. This mode protects packet contents but not the ultimate source and
destination addresses. Use this mode for Windows 2000 client compatibility.
13-24
= No data authentication.
= ESP protocol using HMAC (Hashed Message Authentication Coding) with the
= ESP protocol using HMAC with the SHA-1 hash function using a 160-bit key.
= No packet encryption.
= Use DES encryption with a 56-bit key.
= Use Triple-DES encryption with a 168-bit key. This is the default selection, and it is the
= Apply ESP encryption and authentication to the entire original IP packet (IP header and
= Apply ESP encryption and authentication only to the transport layer segment (data only)
VPN 3000 Concentrator Series User Guide

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents