Applying A Crypto Map To An Interface - HP ProCurve Secure Router 7203 dl Advanced Management And Configuration Manual

Secure router
Hide thumbs Also See for ProCurve Secure Router 7203 dl:
Table of Contents

Advertisement

Virtual Private Networks
Configuring a VPN Using IPSec
Parameter
PFS group
IPSec SA lifetime
8-46
Options (From Most to Least Secure)
• Diffie-Hellman group 2
• Diffie-Hellman group 1
• 2560 to 536,870,912 kilobytes
• 120 to 86,400 seconds (2 minutes
to 24 hours)
You can find the commands for configuring IPSec SA security parameters in
Table 8-15.
PFS Group. By default, IKE refers back to the keys defined by the IKE SA
when generating the keys for the IPSec SA during IKE phase 2. PFS enhances
security by generating entirely new keys. This ensures that even if one key is
comprised, other keys remain secure. If you want to use PFS, you must specify
which Diffie-Hellman group IKE uses to generate the IPSec SA keys. For
example, you could enter this command from the crypto map configuration
mode context:
ProCurve(config-crypto-map)# set pfs group2
IPSec SA Lifetime. You can define the lifetime of an IPSec SA (that is, a
VPN connection) in kilobytes and in seconds. See Table 8-15 for the command
syntax. Enter commands such as:
ProCurve(config-crypto-map)# set security-association lifetime kilobytes 1000000
ProCurve(config-crypto-map)# set security-association lifetime seconds 9600
If you set the SA lifetime in both kilobytes and seconds, the VPN connection
will close after whichever limit is reached first.

Applying a Crypto Map to an Interface

In order for the crypto map to take effect, you must apply it to an interface.
When you apply the crypto map to an interface, you apply the entire set of
crypto map entries with the same name. Configuring multiple crypto map
entries with the same name but different index numbers lets you establish a
VPN connection with multiple peers. It also allows you to create different levels
of security for different sets of traffic by matching entries to various ACLs.
Default
Command Syntax
PFS not used
set pfs [group2 | group1]
8 hours
set security-association
lifetime [kilobytes
<kilobytes> | seconds
<seconds>]

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve secure router 7102 dl

Table of Contents