218
Matrix NAVAN CNX200 System Manual
IPSec
Internet Protocol Security Protocol (IPSec) is a collection of protocols that assist in protecting communications over
IP networks. IPSec protocols work together in various combinations to provide protection for communications. It
provides enhanced security features such as
stronger encryption
and
more comprehensive authentication
. The
primary components of IPSec are:
1.
Encapsulating Security Payload (ESP)
2.
Internet Key Exchange (IKE)
Creating an IPSec Policy
Once you have decided to use IPSec or L2TP over IPSec protocol as the security protocol, the next step is to
create an IPSec Policy.
An IPSec Policy is a set of rules that govern the use of the IPSec protocol. Considering the confidentiality, integrity
and availability of the IPSec implementation, you can develop the IPSec Policy. The security parameters are the
authentication
,
encryption
and the
tunnel settings
. The IPSec Policy contains
Rules
.
Other than the above security parameters, you also need to define the IKE, SA (Security Association) life span,
decide the authentication mode (Main or Aggressive) for the IKE Phase one exchange, and identify the best Diffie-
Hellman (DH) group number.
An IPSec operates as per the steps given below:
•
Initiation of the IPSec process
: The interested traffic on the Client side initiates and sends the request to
start the IPSec process. The NAVAN Server acknowledges the request and starts the IKE process as per
the configured IPSec security policy.
•
IKE phase one:
After initiation of the IKE process, the Security Associations occurs for the security
purpose. Security Associations between the Server and the Client takes place in two phases.
During IKE Phase 1, IKE authenticates the IPSec Clients and negotiates IKE SAs on the basis of the
parameters configured in the selected IPSec Policy. It creates a secure channel between the Server and
the Client to enable IKE exchanges and also for negotiating of IPSec SAs in phase 2.
IKE Phase 1 occurs in two modes:
Main mode
and
Aggressive mode
.
•
Main mode
: Main mode negotiates the establishment of the IKE SA through three pair of messages
(three two-way exchanges). This mode of authentication is more safe but slow. This mode also offers
automatic selection of the peer's proposal, generally making it easier to configure.
•
Aggressive mode
: Aggressive mode negotiates the same parameters as Main mode but through
fewer messages. Aggressive mode negotiates and exchanges key using an exchange of three
messages between IKE Servers.
•
IKE phase two
: The purpose of IKE Phase two is to negotiate IPSec SA parameters as per the selected
IPSec Policy, setup the IPSec tunnel and come to a conclusion to match the IPSec SAs in the clients.
Summary of Contents for NAVAN CNX200
Page 1: ...NAVAN CNX200 System Manual ...
Page 2: ......
Page 3: ...NAVAN CNX200 Office in a Box Solution for Small Businesses System Manual ...
Page 26: ...16 Matrix NAVAN CNX200 System Manual NAVAN CNX226 3G NAVAN CNX226 2G2 ...
Page 27: ...Matrix NAVAN CNX200 System Manual 17 NAVAN CNX208 3G2 NAVAN CNX244 3G2 ...
Page 28: ...18 Matrix NAVAN CNX200 System Manual Application of NAVAN ...
Page 118: ...108 Matrix NAVAN CNX200 System Manual To exit the SA mode click Logout on the top of the page ...
Page 122: ...112 Matrix NAVAN CNX200 System Manual ...
Page 128: ...118 Matrix NAVAN CNX200 System Manual ...
Page 158: ...148 Matrix NAVAN CNX200 System Manual ...
Page 268: ...258 Matrix NAVAN CNX200 System Manual ...
Page 278: ...268 Matrix NAVAN CNX200 System Manual ...
Page 296: ...286 Matrix NAVAN CNX200 System Manual ...
Page 306: ...296 Matrix NAVAN CNX200 System Manual ...
Page 397: ...Matrix NAVAN CNX200 System Manual 387 ...
Page 419: ...Matrix NAVAN CNX200 System Manual 409 1 Click Device Settings Location1 to expand options ...
Page 436: ...426 Matrix NAVAN CNX200 System Manual ...
Page 530: ...520 Matrix NAVAN CNX200 System Manual ...
Page 570: ...560 Matrix NAVAN CNX200 System Manual ...
Page 848: ...838 Matrix NAVAN CNX200 System Manual ...
Page 852: ...842 Matrix NAVAN CNX200 System Manual ...
Page 900: ...890 Matrix NAVAN CNX200 System Manual Pick up the handset Dial 1070 Replace handset ...
Page 912: ...902 Matrix NAVAN CNX200 System Manual Exit System Administrator mode ...
Page 930: ...920 Matrix NAVAN CNX200 System Manual Replace handset ...
Page 994: ...984 Matrix NAVAN CNX200 System Manual You may log out of Jeeves ...
Page 1072: ...1062 Matrix NAVAN CNX200 System Manual To Retrieve Message Wait Pick up the handset Dial 1077 ...
Page 1086: ...1076 Matrix NAVAN CNX200 System Manual To resume outgoing speech Press Flash Key Dial 1052 ...
Page 1216: ...1206 Matrix NAVAN CNX200 System Manual ...
Page 1308: ...1298 Matrix NAVAN CNX200 System Manual The End IP Address ...
Page 1310: ...1300 Matrix NAVAN CNX200 System Manual ...
Page 1356: ...1346 Matrix NAVAN CNX200 System Manual NAVAN Features tested on IP Phones of different Brands ...
Page 1357: ...Matrix NAVAN CNX200 System Manual 1347 ...
Page 1366: ...1356 Matrix NAVAN CNX200 System Manual ...