EasyManua.ls Logo

Case 6401 - Configuration Examples

Case 6401
107 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Case Communications 6401 Rugged ADSL Router Manual Rev 1.5
SECTION 5 ADVANCED CONFIGURATION Page 5.65
5.16.4 CONFIGURATION EXAMPLES
Example 1 Connection to a PIX Firewall
Parameter
Setting
Meaning
IPSec Connection Name
To-Cisco
User definable
Tunnel Mode
ESP
Cisco default tunnel type
Remote IPSec gateway Address
182.12.1.200
IP address of the Cisco PIX WAN port
Tunnel Access from local IP
address
Subnet
Use subnet to allow equipment connected to the
routers to talk over the IPSec tunnel
IP address for VPN
192.168.1.1
Local VPN IP address, use this as default gateway for
equipment
IP Subnet Mask
255.255.255.0
Class C subnet
Tunnel Access from remote IP
address
Subnet
Use subnet to allow equipment connected to a Cisco
PIX to talk over the IPSec tunnel
IP address for VPN
192.168.2.1
Remote VPN IP address
IP Subnet Mask
255.255.255.0
Class C subnet
Key Exchange Method
Auto (IKE)
Authentication Method
Pre-Shared Key
Pre-Shared Key
secret
Type in the secure PSK that the Cisco also uses
Perfect Forward Secrecy
Disable
ADVANCED IKE SETTINGS
Phase 1 Mode
Main
send a proposal containing encryption methods used
Encryption Algorithm
3DES
DES, 3DES, AES-128, AES-192 or AES-256
Integrity Algorithm
SHA1
MD5 (default) , SHA1 (SHA1 used by Cisco PIX)
Select Diffie-Hellman Group
1024bit
768bit, 1024bit, 1536bit, 2048bit, 3072bit, 4096bit,
6144bit or 8192bit
Key Life Time
3600
determines when a new key is generated see below.
Phase 2 Encryption Algorithm
2DES
Integrity Algorithm
SHA1
Select Diffie-Hellman Group
1024bit
Key Life Time (60 3,000,000)
60 seconds to nearly 35 days
3600
Time before tunnel is broken and re-established using
a new key. NB. Every tunnel break removes the users.
Example 2 Manual Key Exchange Method
Parameter
Setting
Meaning
IPSec Connection Name
IPSec1
User definable
Tunnel Mode
AH
Cisco default tunnel type
Remote IPSec gateway
Address
182.12.30.200
IP address of the Cisco PIX WAN port
Tunnel Access from local
IP address
Subnet
Use subnet to allow equipment
connected to the routers to talk over the
IPSec tunnel
IP address for VPN
192.168.10.1
Local VPN IP address, use this as
default gateway for equipment
IP Subnet Mask
255.255.255.0
Class C subnet
Tunnel Access from
remote IP address
Subnet
Use subnet to allow equipment
connected to the Cisco to talk over the
IPSec tunnel
IP address for VPN
192.168.20.1
Remote VPN IP address
IP Subnet Mask
255.255.255.0
Class C subnet
Key Exchange Method
Manual
Encryption Algorithm
DES
Options DES, 3DES or AES
Encryption Key
1234567890abcdef
16 digit DES Key (48 for DES)
Authentication Algorithm
MD5
MD5 or SHA1
Authentication Key
1234567890abcdef1234567890abcdef
32 digit MD5 key (40 for SHA1)
SPI
101
User definable

Table of Contents

Related product manuals