User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Network Security, Authentication and Auditing
115
NOTE: Secure Cli-
ent versions ear-
lier than 3.1 support
only DH-512 key estab-
lishment.
A Secure Client logging on to the Mesh Point must use a key
establishment setting present in the Mesh Point’s configuration.
For information on configuring key establishment on Secure
Clients, refer to the Fortress Secure Client User Guide.
The Mesh Point CLI returns
OK
when settings are successfully
changed.
4.1.6 MSP Re-Key Interval
The re-keying interval is the length of time between new keys
issued by the Mesh Point. View the re-keying interval (among
other security settings) in effect on the Mesh Point with
show
crypto (shown in Section 4.1).
The re-keying interval in effect between the Fortress Mesh
Point and its Clients or other Mesh Points is set, in values
between 1 and 24 hours, with the
set crypto command:
NOTE:
The user can
choose to disable re-
keying ONLY if FIPS mode
is disabled, by choosing a
re-keying interval of 0.
# set crypto -t
<hrs>
The default re-keying interval is 4 hours.
You must be logged on to an
administrator
-level account to
change configuration settings (refer to Section 2.2).
4.1.7 Key Beacon Interval
In order to maintain active, secure connections to other
Fortress devices on the Fortress-secured network, the Mesh
Point transmits network key beacons at regular, user-
configurable intervals. View the key beacon interval (among
other security settings) in effect on the Mesh Point with
show
crypto (shown in Section 4.1).
The Mesh Point’s beacon interval is set in seconds between 0
and 3000, inclusive (a setting of 0 (zero) disables the beacon).
It is configured with the
set crypto command using the -b
switch:
# set crypto -b
<secs>
The default beacon interval is 30 seconds.
You must be logged on to an
administrator
-level account to
change configuration settings (refer to Section 2.2).
4.1.8 Fortress Legacy Devices
You can configure the Mesh Point to support legacy devices.
View the current legacy device setting (among other security
settings) in effect on the Mesh Point with
show crypto (shown
in Section 4.1).
Enable or disable support for legacy devices with
set crypto:
# set crypto -legacy on|off
You must be logged on to an
administrator
-level account to
change configuration settings (refer to Section 2.2).