|
Function Specification
109
Source address specification
Fixed setting
Peer
1
IKEv2
extension
IKE SA deletion
Manual deletion
IKE SA deletion when “delete payload” is received
“delete payload: transmission when IKE SA is deleted
Rekey extension of IPsec SA/IKE SA
Continuous connection
Continuous connection
without traffic
On-demand connection
Rekey with traffic
There is traffic, but
rekey is not done
Keepalive
DPD
Send interval
specification
Retry out frequency
specification
(IKE SA retry
interval/frequency
applies in IKEv2)
NAT traversal
1 session
Negotiation direction limitation
both, initiator, responder
IPsec
Mode
Tunnel mode
Security protocol
ESP
Supported
algorithm
Encryption
3DES, AES-128, AES-192, AES-256, NULL
Authentication
HMAC-MD5-96, HMAC-SHA-1-96, HMAC-SHA-2-256-
128
PFS
768bit (group1), 1024bit (group2), 1536bit (group5),
2048bit (group14), Disabled
Fragmentation method
post-fragment
Send
Receive
pre-fragment
Send
Receive
SA
IPsec ID
authentication
Local-id/remote-id (IPv4 address and IPv4 prefix)
Lifetime
Time setting, data amount setting
Rekey timing
Remaining time setting
IPsec
extension
IPsec SA deletion
Manual deletion
IPsec SA deletion when “delete payload” is received
“delete payload” transmission when IPsec SA is
deleted
DF bit control
AUTO (Override DF bit)