iSG4F
User’s Manual
iS5 Communications Inc.
133
Supported mode
o
Transport (yes)
o
Tunnel (no)
Authentication s HASH algorithms
o
Secure Hash Algorithm SHA-1 (160 bit)
o
Secure Hash Algorithm SHA-2 (256 |512 bit)
o
Message Digest (MD5) (128 bit)
Perfect Forward Secrecy type (PFS)
Encryption algorithm
o
Advanced Encryption Standard (AES)
128 and 256 key size options
symmetric algorithm
o
Triple Data Encryption Algorithm (3DES)
comprises of three DES keys, K1, K2 and K3, each of 56 bits
Life time
o
Soft – hard coded. At this threshold value the IKE starts a new phase 2 exchange.
o
Hard- SA which has exceeded this threshold value will be discarded.
24.16
IPSec Command Association
Below are the detailed configuration fields of the IPSec in their respective association to the ISAKMP
structure.
Highlighted in blue are the CLI names of the configurable fields.
Enable IPSec
{enable |disable}
Settings
Log level (
log-level)
Dead Peer Discovery
delay
(dpd-delay)
max failure
(dpd-maxfail)
max retires
(dpd-retry)
flush Security Association
(flush-sa proto)