IPSec Security Association Settings

Peer ID 

ID that sets the IP address of the peer or end point of the IPSec tunnel. 

Security Filter 

Filter that determines which packets are to be handed to a particular security asssociation configuration. See Configure Filters for more information about filters. 

Note - If the security asociation is atached directly to a network interface, user, or location, you do not need to set a security filter. 

Security Proposal 

Protocol and encryption that are used to provide security for the security association. The protocol can be either IP authentication header (AH) or encapsulating security payload (ESP). The encryption standard can be DES, 3DES, or MD5. 

ESP Inbound SPI 

Security parameter index for the ESP protocol used on the remote node. The destination value assigned to the local node matches the local value at the remote end. 

AH Inbound SPI 

Security parameter index for the AH protocol used on the remote node. The local value assigned to the local node matches the destination value at the remote node. 

ESP Outbound SPI 

Security parameter index for the ESP protocol used on the local node---this PortMaster. The local value assigned to the local node matches the destination value at the remote node. 

AH Outbound SPI 

 

Security parameter index for the AH protocol used on the local node---this PortMaster. The destination value assigned to the local node matches the local value at the remote end. 

ESP Inbound Keys

ESP Outbound Keys

AH Inbound Keys

AH Outbound Keys

Keys can be entered by using hexadecimal (base 16), decimal (base 10), or binary (base 2). Keys are written similar to filter IP addresses.

Keys must fall on 8-bit boundaries. Some protocols only allow specific key lengths, while others allow a range of lengths. When keys are stored or displayed, they are in hexadecimal format.

Local Address

IP Address of the PortMaster to be placed in outgoing packets.