Configuring VPN
IPSec Policy
SRP 521 VoIP Gateway Administration Guide
79
6
REVIEW DRAFT — CISCO CONFIDENTIAL
Field
Description
General
Policy Number
The policy index that you are going to configure.
Enable
If this check-box is enabled, this tunnel will be activated
after the Submit button is pressed.
Policy Name
A unique name for bringing up a tunnel.
Policy Type
There are two types, Auto Policy and Manual Policy. The
Auto Policy type will use IKE protocol to negotiate
random keys, therefore it first requires an IKE policy as
well. The Manual Policy type will NOT use IKE, which is
more simple, but less secure.
Remote Endpoint
The remote gateway that you are going to connect to
establish a IPSec VPN tunnel. Your choices are IP
Address, Any, or FQDN. The Any option will only appear
in Auto Policy and is available to increase security level
for roaming users. The FQDN option requires a Full
Qualified Domain Name. Ensure that the domain name
can be resolved into IP address by a correct DNS server
if the VPN tunnel can not be established.
Encryption
Algorithm
Encryption algorithm of IPSec SA. Choices are DES,
3DES, AES128, AES192, and AES256.
Integrity Algorithm
Authentication algorithm for IPSec SA. Choices are MD5
and SHA1.
Auto Policy Parameters
PFS
Perfect Forward Secrecy, if enabled, it can prevent a
new key from being predictable by previous one.
Pre Shared Key
Used by IKE.
SA Lifetime
IPSec SA life time in seconds.
Manual Policy Parameters
SPI Incoming
A HEX value, range from 0x100 to 0xffffffff.
SPI Outgoing
A HEX value, range from 0x100 to 0xffffffff.