Installation guide
Switch Security 6-61
4. Highlight an existing policy and click the Edit button to revise the policy’s existing encryption scheme,
hash value, authentication type, SA lifetime and DH group.
The sequence number cannot be revised.
5. Select an existing policy and click the Delete button to remove it from the table.
Authentication Type Displays the authentication scheme used to validate the identity of each peer. Pre-
shared keys do not scale accurately with a growing network but are easier to
maintain in a small network. Options include:
• Pre-shared Key - Uses pre-shared keys.
• RSA Signature - Uses a digital certificate with keys generated by the RSA
signatures algorithm.
SA Lifetime (sec.) Displays an integer for the SA lifetime. The default is 60 seconds. With longer
lifetimes, security defines future IPSec security associations quickly. Encryption
strength is great enough to ensure security without using fast rekey times.
Motorola recommends using the default value.
DH Group Displays the Diffie-Hellman (DH) group identifier. IPSec peers use the defined
value to derive a shared secret without transmitting it to one another.
NOTE: 192-bit AES and 256-bit AES are not supported for manual IPSec sa
configurations.