Avaya Business Secure Router 252 Configuration - Basics Manuel d'utilisateur Page 241

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 460
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 240
Chapter 13 VPN 241
Nortel Business Secure Router 252 Configuration — Basics
Diffie-Hellman (DH) Key Groups
Diffie-Hellman (DH) is a public-key cryptography protocol that allows two
parties to establish a shared secret over an unsecured communications channel.
Diffie-Hellman is used within IKE SA setup to establish session keys. 768-bit
(Group 1 - DH1), 1 024-bit (Group 2 – DH2) and 1 536-bit (Group 5 - DH5)
Diffie-Hellman groups are supported. Upon completion of the Diffie-Hellman
exchange, the two peers have a shared secret, but the IKE SA is not authenticated.
For authentication, use preshared keys.
Perfect Forward Secrecy (PFS)
Enabling PFS means that the key is transient. The key is thrown away and
replaced by a brand new key using a new Diffie-Hellman exchange for each new
IPSec SA setup. With PFS enabled, if one key is compromised, previous and
subsequent keys are not compromised, because subsequent keys are not derived
from previous keys. The (time consuming) Diffie-Hellman exchange is the
trade-off for this extra security.
This can be unnecessary for data that does not require such security, so PFS is
disabled (None) by default in the Business Secure Router. Disabling PFS means
new authentication and encryption keys are derived from the same root secret
(which can have security implications in the long run) but allows faster SA setup
(by bypassing the Diffie-Hellman key exchange).
Configuring advanced Branch office setup
Select one of the VPN rules in the VPN Summary screen and click Edit to
configure the rule. The basic IKE rule setup screen displays.
In the VPN Branch Office Rule Setup screen, click the Advanced button to
display the VPN Branch Office Advanced Rule Setup screen.
Vue de la page 240
1 2 ... 236 237 238 239 240 241 242 243 244 245 246 ... 459 460

Commentaires sur ces manuels

Pas de commentaire