|
Function Specification
105
■
IKEv2
[IKEv2 overview]
IKEv2 features will be outlined for those using IKEv1. IKEv2 is not compatible with IKEv1 and the terms used are
different.
ISAKMP-SA, IPsec-SA equivalent functions are KE-SA and Child-SA respectively.
Hash algorithm is equivalent to authentication algorithm and a pseudo-random number algorithm.
The concept of main mode and aggressive mode is removed and operation is shared.
Phase1-ID, Phase2-ID are also shared, and only a pair of local-ID and remote-ID are obtained.
[Key Management Method]
IKEv2 requires a pre-shared key for the device and a pre-shared key setting for the remote device.
*In the case of IKEV1, use a common pre-shared key on local device and the remote device.
[IKEv2 Sequence]
●
IKE_SA_INIT exchange
:
IKE_SA negotiation and private key sharing
●
IKE_AUTH exchange
:
Peer authentication CHILD_SA negotiation
[Connection method]
To create an IPsec tunnel, continuous and on-demand connection can be selected.
By associating with
“
Rekey
”
setting, the following three setting patterns can be set from Web setting:
IKE_SA_INIT Exchange
(request)
User Traffic
Protected with
IKE_SA
Protect with
CHILD_SA
IKE_SA_INIT Exchange
(response)
IKE_AUTH Exchange
(request)
IKE_AUTH Exchange
(response)
Initiator
Responder