Perfect Forward Secrecy; Lifetime Measurement; Data Lifetime; Time Lifetime - Cisco VPN 3000 User Manual

Table of Contents

Advertisement

Perfect Forward Secrecy

This parameter specifies whether to use Perfect Forward Secrecy, and the size of the numbers to use, in
generating Phase 2 IPSec keys. Perfect Forward Secrecy is a cryptographic concept where each new key
is unrelated to any previous key. In IPSec negotiations, Phase 2 keys are based on Phase 1 keys unless
Perfect Forward Secrecy is specified. Perfect Forward Secrecy uses Diffie-Hellman techniques to
generate the keys.
Click the drop-down menu button and select the Perfect Forward Secrecy option:

Lifetime Measurement

This parameter specifies how to measure the lifetime of the IPSec SA keys, which is how long the IPSec
SA lasts until it expires and must be renegotiated with new keys. It is used with the Data Lifetime or Time
Lifetime
Click the drop-down menu button and select the measurement method:

Data Lifetime

If you select Data or Both under Lifetime Measurement above, enter the number of kilobytes of payload
data after which the IPSec SA expires. Minimum is 100 KB, default is 10000 KB, maximum is
2147483647

Time Lifetime

If you select Time or Both under Lifetime Measurement above, enter the number of seconds after which the
IPSec SA expires. Minimum is 60 seconds, default is 28800 seconds (8 hours), maximum is
2147483647
VPN 3000 Concentrator Series User Guide
Configuration | Policy Management | Traffic Management | Security Associations | Add or Modify
Disabled
= Don't use Perfect Forward Secrecy. IPSec Phase 2 keys are based on Phase 1 keys. This
is the default selection.
Group 1 (768-bits)
= Use Perfect Forward Secrecy, and use Diffie-Hellman Group 1 to generate IPSec
Phase 2 keys, where the prime and generator numbers are 768 bits. This option is more secure but
requires more processing overhead.
Group 2 (1024-bits)
= Use Perfect Forward Secrecy, and use Diffie-Hellman Group 2 to generate IPSec
Phase 2 keys, where the prime and generator numbers are 1024 bits. This option is most secure but
requires the most processing overhead.
parameters below.
= Use time (seconds) to measure the lifetime of the SA (the default). Configure the Time
Time
Lifetime
parameter below.
Data
= Use data (number of kilobytes) to measure the lifetime of the SA. Configure the Data Lifetime
parameter below.
= Use both time and data, whichever occurs first, to measure the lifetime. Configure both Time
Both
Lifetime
and Data Lifetime parameters.
= No lifetime measurement. The SA lasts until the connection is terminated for other reasons.
None
KB.
seconds (about 68 years).
13-25

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents