Chapter 3 – RouteFinder Software Operation
Multi-Tech RouteFinder RF650VPN User Guide
127
Manual SA (Secure Association)
With Perfect Secret Forwarding enabled and manual Secure Association selected, the New
connection menu is re-displayed with Manual SA entry fields, requiring SPI and ESP information for
manual keying.
The
SPI
is a unique identifier in the SA that allows the receiving computer to select the SA under which a
packet will be processed.
SPIBASE
: the SPI (
Security Parameters Index
) Base: A number needed by the manual keying code. Enter
any hexadecimal value (3-digit hex number). If you have more than one manual connection, then the
SPIBASE
must be different for each manual connection.
ESP
: the ESP (
Encapsulating Security Payload
) method: enter an option for ESP, (typically IPSEC
encryption mode). Settings here are for encryption using triple DES and authentication using MD5. The
selection
3des-md5-96
is the default.
Note: Encryption without authentication should not be used; it is insecure.
ESPENCKEY
: the ESP (
Encapsulating Security Payload
) ENKEY: no entry required in current RouteFinder
versions; this screen displayed only in early versions and was removed in subsequent versions, so please
ignore it.
ESPENCKEY: the ESP (Encapsulating Security Payload) ENKEY: enter the Key for ESP encryption
(a 192-bit hex number for triple DES). For example:
0x01234567_89abcdef_02468ace_13579bdf_12345678_9abcdef0 .
ESPAUTHKEY: the ESP (Encapsulating Security Payload) AUTHKEY: enter the Key for ESP
authentication (a 128-bit hex number for MD5). For example:
0x12345678_9abcdef0_2468ace0_13579bdf .