Quadro Quadro16xi Installation Guide Page 119

  • Download
  • Add to my manuals
  • Print
  • Page
    / 150
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 118
Quadro Manual II: Administrator's Guide Administrator’s Menus
Quadro2x, 2xi, Quadro4x, 4xi, Quadro16x, 16xi; (SW Version 5.2.x) 118
The Peer type drop down list is used to choose the remote
machine type for the IPSec Connection to be established. If the
list does not include the required type of machine, choose
Other.
The VPN Network Topology drop down list allows you to select
the location of the peers participating to the VPN connection.
The following options are present in the list:
Quadro<>Peer – direct connection between Quadro and a
peer.
Quadro<>[Internet]<>Peer – connection between Quadro
and peer over Internet.
Quadro<>NAT<>[Internet]<>Peer – connection between
Quadro and peer over Internet through Quadro provider’s
NAT.
Quadro<>[Internet]<>NAT<>Peer – connection between
Quadro and peer over Internet through peer provider’s
NAT.
Fig. II-198: IPSec Connection Wizard - Add IPSec Connection
The next page of the wizard is IPSec Keying Properties offers
the choice between automatic and manual keying.
Auto Keying requires the IKE (Internet Key Exchange) and
ESP (Encapsulated Security payload) settings defined.
Encryption and Authentication parameters should be defined
for each of these standards, as well as for the Manual Keying.
The Encryption drop down list offers the following standards
for selection:
Single DES (Data Encryption Standard) is a block
cipher algorithm with 64-bit blocks and a 56-bit
key. This algorithm is considered to be unsecure
for sensitive information.
Triple DES (Triple DES) uses three DES
encryptions on a single data block with three
different keys to achieve a higher security than is
available from a single DES pass.
AES (Advanced Encryption Standard) is a
computer security standard, which became
effective on May 26, 2002 by NIST to replace
DES. The cryptography scheme is a symmetric
block cipher, which encrypts and decrypts 128-bit
blocks of data. Lengths of 128, 192, and 256 bits
are standard key lengths used by AES.
Fig. II-199: IPSec Connection Wizard -IPSec Connection Properties
The area Authentication offers the following parameters to be selected:
SHA (Secure Hash Algorithm) is a strong digest algorithm proposed by the US NIST (National Institute of Standards and Technology)
agency as a standard digest algorithm and is used in the Digital Signature standard, FIPS number 186 from NIST. SHA is an improved
variant of MD4 producing a 160-bit hash. SHA and MD5 are the message digest algorithms available in IPSEC.
SHA1 is an enhanced version of SHA. It works with checksums like MD5 does, but it makes a longer hash.
MD5 (Message Digest) is a hash algorithm that makes a checksum over the messages. The checksum is sent with the data and
enables the receiver to notice whether the data has been altered.
The Diffie-Hellman parameter is available for Auto Keying only and is used to determine the length of the base prime numbers used during the key
exchange process. The cryptographic strength of any key derived depends, in part, on the strength of the Diffie-Hellman group, which is based upon
the prime numbers.
Group 2048 (high) is stronger (more secure) than Group 2 (medium), which is stronger than Group 1 (low). Group 1 provides 768 bits of keying
strength, Group 2 provides 1024 bits, and Group 2048 provides 2048 bits. If mismatched groups are specified on each peer, negotiation fails.
Depending on whether the automatic keying type or the manual one has been selected, the button Next will lead you to the Automatic Keying or
Manual Keying page.
The third page of the IPSec Connection wizard for Automatic Keying is used to setup a type of password (Shared Secret) or the RSA public key to
secure your IPSec Connection. The functionality of Perfect Forward Secrecy (PFS) can be added to both. Following ways of automatic keying are
available.
Page view 118
1 2 ... 114 115 116 117 118 119 120 121 122 123 124 ... 149 150

Comments to this Manuals

No comments