19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

<strong>The</strong> transport mode is only permitted for host-to-host communication,<br />

passthrough only for manual key management.<br />

auto = start<br />

If the parameters plutoload and plutostart are set to the special value %search,<br />

then the parameter auto determines whether the present connection is<br />

automatically loaded into the pluto database and activated. In our example the<br />

connection is to be directly activated, so the parameter auto is therefore set to<br />

start.<br />

auth = esp<br />

<strong>The</strong> parameter auth determines which of the two IPSEC functions,<br />

Encapsulating Security Payload (ESP) or Authentication Header (AH) is used<br />

during authentication. In the present case both encryption and authentication<br />

with ESP are possible. This is the standard setting.<br />

authby = rsasig<br />

It is recommended that authentication is performed using digital signatures<br />

with the RSA algorithm (rsasig setting). This provides a higher level of<br />

security than the "shared secrets" procedure (secret setting) as well as<br />

simplifying administration.<br />

pfs = yes<br />

pfs stands for Perfect Forward Secrecy and means that messages which have<br />

been exchanged in the past are not compromised even if the private keys of<br />

the two gateways become known. (However, the security of future<br />

connections can no longer be assured.) <strong>The</strong> recommended setting for this<br />

parameter is the default value yes.<br />

keyingtries = 0<br />

Parameter keyingtries specifies the maximum permitted number of attempts at<br />

establishing or updating the corresponding connection. It is recommended that<br />

the special value 0 is entered, i.e. so that there is no limit on the number of<br />

attempts. <strong>The</strong> preconfigured value 3 for the parameter keyingtries is<br />

inadequate for most applications.<br />

left = <br />

right = <br />

<strong>The</strong> IP addresses of the two gateways are set through parameters left and right.<br />

It is recommended that the IP addresses are entered numerically rather than<br />

using the special value %defaultroute. By performing a comparison with the<br />

IP addresses which have been assigned to the corresponding network<br />

interfaces of the <strong>IT</strong> system, FreeS/WAN can detect which of the two roles (left<br />

or right) this <strong>IT</strong> system is assuming.<br />

leftnexthop = <br />

rightnexthop = <br />

For parameters leftnexthop and rightnexthop, in each case the IP address of the<br />

component which forwards the packets over the insecure network should be<br />

entered. In the present example this component is part of the firewall system.<br />

However, depending on the segmentation and layout of the active network<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!