Cisco VPN 3000 Betriebsanweisung Seite 274

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 502
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 273
13 Policy Management
13-24
VPN 3000 Concentrator Series User Guide
IPSec Parameters
These parameters apply to IPSec SAs, which are Phase 2 SAs negotiated under IPSec, where the two
parties establish conditions for use of the tunnel.
Authentication Algorithm
This parameter specifies the data, or packet, authentication algorithm. Packet authentication proves that
data comes from whom you think it comes from; it is often referred to as data integrity in VPN
literature. The IPSec ESP (Encapsulating Security Payload) protocol provides both encryption and
authentication.
Click the drop-down menu button and select the algorithm:
None = No data authentication.
ESP/MD5/HMAC-128 = ESP protocol using HMAC (Hashed Message Authentication Coding) with the
MD5 hash function using a 128-bit key. This is the default selection.
ESP/SHA/HMAC-160 = ESP protocol using HMAC with the SHA-1 hash function using a 160-bit key.
This selection is more secure but requires more processing overhead.
Encryption Algorithm
This parameter specifies the data, or packet, encryption algorithm. Data encryption makes the data
unreadable if intercepted.
Click the drop-down menu button and select the algorithm:
Null = No packet encryption.
DES-56 = Use DES encryption with a 56-bit key.
3DES-168 = Use Triple-DES encryption with a 168-bit key. This is the default selection, and it is the
most secure.
Encapsulation Mode
This parameter specifies the mode for applying ESP encryption and authentication; in other words, what
part of the original IP packet has ESP applied.
Click the drop-down menu button and select the mode:
Tunnel = Apply ESP encryption and authentication to the entire original IP packet (IP header and
data), thus hiding the ultimate source and destination addresses. This is the default selection, and it
is the most secure.
Transport = Apply ESP encryption and authentication only to the transport layer segment (data only)
of the original IP packet. This mode protects packet contents but not the ultimate source and
destination addresses. Use this mode for Windows 2000 client compatibility.
Seitenansicht 273
1 2 ... 269 270 271 272 273 274 275 276 277 278 279 ... 501 502

Kommentare zu diesen Handbüchern

Keine Kommentare