508
configuring IPsec interface backup, 185
configuring the IPsec session idle
timeout, 168
coo
kie challenging configuration, 221
disa
bling next payload field checking, 208
displ
aying, 178
enabli
ng fragmentation before/after
encryption, 172
enabli
ng invalid SPI recovery, 170
enabli
ng IPsec module backup, 167
enabli
ng the encryption engine, 167
enabli
ng transparent data transmission
without NAT, 172
encryption al
gorithms, 150
encryption ca
rd configuration, 183
FIPS complia
nce, 154
GDOI IPse
c policy application to
interface, 464
GDOI IPse
c policy configuration, 463
GDOI mo
de, 151
global IKEv2 para
meters configuration, 221
IKE
ACL configuration error, 218
IKE configura
tion, 200, 203, 209
IKE configura
tion (aggressive mode/RSA
signature authentication), 213
IKE configura
tion (main mode/pre-shared key
authentication), 209
IKE data authenticatio
n, 200
IKE DPD detector
configuration, 208
IKE failed to
establish an IPsec tunnel, 217
IKE functions, 201
IKE identity a
uthentication, 200
IKE identity p
rotection, 200
IKE invalid us
er ID, 216
IKE negotiation mode, 150
IKE operation
, 200
IKE peer conf
iguration, 205
IKE proposal config
uration, 204
IKE proposal mismat
ch, 217
IKE relationship, 202
I
KE security mechanism, 200
IKE troublesh
ooting, 216
IKE-base
d tunnel configuration, 181
IKEv2 certificate authenti
cation, 233
IKEv2 configuration, 219, 220, 227
IKEv2 DPD configuration, 221
IKEv2 keyring config
uration, 224
IKEv2 negotiation failure trouble
shooting
(IPsec tunnels cannot be set up), 240
IKEv2 negotiation failure trouble
shooting (no
proposal match), 240
IKEv2 new feature, 219
IKEv2 policy config
uration, 223
IKEv2 pre-sh
ared key authentication, 227
IKEv2 profile config
uration, 225
IKEv2 proposal config
uration, 223
IKEv2 troublesho
oting, 240
impleme
ntation, 154
impleme
ntation on an encryption card, 151
IPv6. See IPv6 IPsec
ISAKMP
mode, 151
kee
palive timers setting, 207
limits on the numbe
r of IKEv2 SAs setting, 222
maintaining, 178
manual m
ode, 151
mirro
r image ACLs, 157
name for the l
ocal security gateway
configuration, 203
NA
T keepalive timer setting, 207
non-mirror im
age ACLs, 157
packet inform
ation pre-extraction
configuration, 170
packet inform
ation pre-extraction configuration on
the IPsec tunnel interface, 176
policy ap
plication to interface, 165
policy configu
ration, 160, 160
policy configu
ration (IKE-based), 161
profile config
uration, 174
prote
ction mode, 158
proto
cols and standards, 154
QoS policy a
pplication to IPsec tunnel
interface, 177
RIPng co
nfiguration, 193
RRI, 153
RRI configu
ration, 171, 196
SA, 150
SA
setup mode, 151
se
curity group domain VPN
configuration, 453, 465
se
curity PKI configuration, 241, 243, 252
sha
red source interface policy group
configuration, 169
transfo
rm set configuration, 158
tunnel, 151
tunnel config
uration, 179
tunnel interfa
ce, 152
tunnel interfa
ce configuration, 175, 189
tunnel interfa
ce-based implementation, 173
I
Psec protection
aggregation mode, 158
stand
ard mode, 158
IPs
ec tunnel interface