SIP User's Manual
3.3.4.6
Configuring the IP Security Proposal Table
The 'IP Security Proposals Table' page is used to configure Internet Key Exchange (IKE)
with up to four proposal settings. Each proposal defines an encryption algorithm, an
authentication algorithm, and a Diffie-Hellman group identifier. The same set of proposals
apply to both Main mode and Quick mode.
Note:
To configure IP Security Proposals:
1.
Open the 'IP Security Proposals Table' page (Configuration tab > Security Settings
menu > IPSec Proposal Table
In the figure above, two proposals are defined:
•
Proposal 0: AES, SHA1, DH group 2
•
Proposal 1: 3DES, SHA1, DH group 2
Note that with this configuration, neither DES nor MD5 can be negotiated
2.
Select an Index, click Edit
3.
Click
Apply
4.
To save the changes to flash memory, refer to ''
To delete a proposal, select the relevant Index number, and then click Delete
Table 3-12: IP Security Proposals Table Configuration Parameters
Parameter Name
Encryption Algorithm
[IPsecProposalTable_EncryptionAlgorithm]
Authentication Algorithm
[IPsecProposalTable_AuthenticationAlgorithm]
Version 6.0
You can also configure the IP Security Proposals table using the ini file table
parameter IPsecProposalTable (refer to ''Security Parameters''
Figure 3-63: IP Security Proposals Table
, and then modify the proposal as required.
.
).
Saving Configuration''
Determines the encryption (privacy) algorithm.
[0]
NONE
[1]
DES CBC
[2]
3DES CBC
[3]
AES (default)
Determines the message authentication
(integrity) algorithm.
[0]
NONE
[2]
HMAC SHA1 96
[4] HMAC MD5 96 (default)
95
3. Web-Based Management
on page
on page
.
Description
March 2010
271
).
199
.