18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring VPN Security Associations<br />

Entering Manual<br />

information on the<br />

Authentication tab<br />

13-62 Configuring Virtual Private Networks<br />

The Manual screen in the Authentication window is used to define<br />

manual authentication for this VPN association. This means that only a<br />

remote peer that has entered the exact same manual key value will<br />

have access through this VPN association. To configure manual<br />

authentication, follow the steps below.<br />

1. In the IPSEC Transformations drop-down list, select the appropriate form<br />

<strong>of</strong> IPsec transformation. The valid options are:<br />

Authentication Header (AH)—Provides authentication only.<br />

Encapsulating Security Payload (ESP)—Provides encryption only.<br />

Separate AH + ESP—Performs separate transformations for<br />

authentication and encryption.<br />

Combined ESP + AH—Performs a single transformation that<br />

provides authentication and encryption.<br />

2. In the Authentication Hash drop-down list, select the type <strong>of</strong><br />

authentication you and the remote end have chosen to use. The valid<br />

options are:<br />

HMAC-SHA1-96<br />

HMAC-MD5-96<br />

3. In the Encryption drop-down list, select the type <strong>of</strong> encryption you and<br />

the remote end have chosen to use. The choices are:<br />

Encryption type Key length<br />

AES256 256-bit<br />

AES128 128-bit<br />

CAST128 128-bit<br />

3DES 168-bit<br />

DES 56-bit<br />

Null 0<br />

4. To define keys and SPI index values, click Generate Keys. You can type<br />

your own unique key and SPI index, but it is not recommended.<br />

Since manually generating random keys is difficult, the <strong>Sidewinder</strong> <strong>G2</strong><br />

provides randomly generated authentication and encryption keys and<br />

Security Parameters Index (SPI) value for you and the remote end to use.<br />

It is highly recommended that you use the default keys provided. You<br />

must send these keys and SPI values to the remote end for them to use.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!