NetModule NB1600 User Manual page 68

Hide thumbs Also See for NB1600:
Table of Contents

Advertisement

Detection cycle): The delay (in seconds) between DPD keepalives that are sent for this
connection (default 30 seconds)
Failure threshold: The number of unanswered DPD requests until the IPsec peer is
considered dead (the router will then try to re-establish a dead connection auto-
matically)
IKE Authentication
NetModule routers support IKE authentication through pre-shared keys (PSK) or cer-
tificates within a public key infrastructure.
Using PSK requires the following settings:
PSK: The pre-shared key used to authenticate at the peer
Local ID Type: The type of identification for the local ID which can be a FQDN, username@FQDN
or IP address
Local ID: The local ID value
Local ID Type: The type of identification for the remote ID
Remote ID: The remote ID value
When using certificates you would need to specify the operation mode. When run as
PKI client you can create a Certificate Signing Request (CSR) in the certificates section
which needs to be submitted at your Certificate Authority and imported to the router
afterwards. In PKI server mode the router represents the Certificate Authority and
issues the certificates for remote peers.
IKE Proposal
This section can be used to configure the phase 1 settings:
Negotiation mode: Choose the desired negotiation mode. Preferably, main mode should
be used but aggressive mode might be applicable when dealing with dynamic
endpoint addresses.
Encryption algorithm: The desired IKE encryption method (we recommend AES256)
Authentication algorithm: The desired IKE authentication method (we prefer SHA1
over MD5)
IKE Diffie-Hellman Group: The IKE Diffie-Hellman Group
SA life time: The lifetime of Security Associations
Perfect Forward Secrecy: Specifies whether Perfect Forward Secrecy (PFS) should be
used. This feature increases security as PFS avoids penetration of the key-exchange
protocol and prevents compromisation of previous keys.
IPsec Proposal
This section can be used to configure the phase 2 settings:
Encapsulation mode: The desired encapsulation mode (Tunnel or Transport)
NB1600 User Manual
68

Hide quick links:

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the NB1600 and is the answer not in the manual?

Table of Contents