104
Function Specification
|
3.6.14.
IPsec
This product supports IPsec communication. IPsec stands for IP security protocol, and it is used for Internet-VPN with
a protocol for encrypting IP packets for secure communication. Main features are the encryption and authentication
functions. Encryption guarantees confidentiality by means of data encryption. Authentication can detect
peer’s
authentication and alteration of packets. In addition, the IPsec communication on this product works with the
security/scan function.
For the IPsec setting method, refer to Section 5.7.16.
IKEv1 and IKEv2 can be used.
Although IKEv2 is not compatible with IKEv1, the operation specification which was unclear in IKEv1 protocol has
been clarified, and is characterized by the support of authentication methods other than the pre-shared key, and
protocol design considering fault tolerance. Refer to Section 5.7.16 for the setting contents. Note that the IKEV1 and
IKEv2 are very different.
[Encryption]
Tunnel mode that encrypts the entire IP packet using ESP (Encapsulating Security Payload) is supported.
■
IKEv1
[Key exchange type]
Main mode and aggressive mode are supported. The key exchange type can be chosen according to the connected
line type (IP address allocation method).
Main mode: Used when product at both ends of IPsec have fixed IP addresses
Aggressive mode: Used when the other product has a dynamic IP address
Center Router
SA3500G
Center
Internet
Location
1
Location
2
SA3500G
Site
WAN
Internet or Data
Communications
Provider
SA3500G
WAN
Center
Fixed IP
Fixed IP
Dynamic IP
Fixed IP
Main Mode
Aggressive Mode
SA3500G