10.12.2012 Views

Administration HiPath 3000/5000 V7 IP systems

Administration HiPath 3000/5000 V7 IP systems

Administration HiPath 3000/5000 V7 IP systems

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>3000</strong>sb4.fm<br />

<strong>HiPath</strong> <strong>3000</strong>/<strong>5000</strong> in the LAN Network For internal use only<br />

HG 1500 V3.0<br />

There is, however, no option to automatically transfer such certificates to clients; every such<br />

transfer must be manually performed – with disks, for example.<br />

Any subsequent certificate management, such as monitoring the period of validity or allocating<br />

certificates to client data, must also be done manually.<br />

The HG 1500 V3.0 can create CRLs (Certificate Revocation Lists) of certificates that are considered<br />

insecure and therefore are declared invalid before the end of the normal period of validity.<br />

These lists must be distributed manually.<br />

HG 1500 V3.0 can work with certificates from external CAs. However, they can also issue certificates<br />

which can be used by other tunnel endpoints to authenticate themselves in a VPN. This<br />

function is called "Lightweight CA" and requires a separate license.<br />

4.5.10.5 Data Security<br />

The HG 1500 V3.0 supports ESP to protect utility data during transmission over the VPN.<br />

DES, Triple DES (3DES) and AES are available as encryption algorithms.<br />

HMAC-SHA1 and HMAC-MD5 are supported as MAC algorithms (MAC – Message Authentication<br />

Code).<br />

The HG 1500 V3.0 supports X.509 certificates as well as DSA and RSA, two public key algorithms,<br />

and pre-shared keys for authenticating VPN subscribers.<br />

P31003-H3570-Y100-4-7618, 2007-10-31<br />

4-42 <strong>HiPath</strong> <strong>3000</strong>/<strong>5000</strong> <strong>V7</strong>, System Description

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!