Owner's Manual
431
Figure 13-11. Adaptive Services—IP Sec Proposal
The fields:
-
Description
—A text description of the proposal.
-
Authentication Algorithm
—Select from the pick list:
hmac-md5-96
(128 bit) or
hmac-sha1-96
(160 bit).
-
Authentication Method
—Select from the pick list alternatives:
dsa-signatures, rsa-signatures,
or
pre-shared key.
-
Diffie Hellman Group
—Select from the pick list:
-
Encryption Algorithm
—Select from the pick list:
3des-cbc
(1192 bits), or
dec-cbc
(48 bits)
-
Lifetime
—The lifetime of an IPSec SA. Can be from 180 - 86400 seconds. The default is 28,800
seconds.
The
Configure
button at the bottom of the screen executes the desired configuration on the
selected equipment.Click the
Refresh
button to re-query for these items.
IP-Security Policies
These policies define a combination of security parameters (IPSec/IKE proposals) used during
IPSec/IKE negotiation. The application seeks a proposal that is the same on both peers. It makes a
match when both policies from the two peers have a proposal that contains the same configured
attributes
This device driver also supports configuring IP Security Policies as a group operation.
Consult the following sections for the field definitions in the group operations screen.