View Categories

IPsec

This section describes the operation of the "IPsec" screen.
Here, you can check the IPsec connection status, add or edit settings, etc.

本マニュアルでの IPsec 構成

This manual describes the IKEv2/IPsec VPN connection operating between AG10 and AC15, organizing its basic configuration, cryptographic parameters, and communication patterns.

Overall overview of VPN connections
  • Connection Name: sa01
  • Protocol used: IKEv2 (phase 1)
  • Authentication method: Both parties use pre-shared keys
    • Local AG10 side IP: 1 192.168.1.197
    • Remote AC15 side IP: 1 192.168.1.113
  • Child Connection (Child SA):
    • Traffic Selector:. 192.168.0.0/24 === 192.168.0.0/24
    • Communication mode: Tunnel mode (TUNNEL)
Encryption parameters
  • IKE(Phase 1)
    • Encryption: 1 AES_CBC_128
    • Authentication HMAC_SHA1_96
    • PRF (Pseudo-Random Function): The HMAC_SHA2_256
    • Diffie-Hellman Group:. MODP_2048
  • IPsec(Phase 2/Child SA)
    • Encryption: 1 AES_CBC_128
    • Authentication HMAC_SHA2_256_128

Click [Network] > [IPsec] on the side menu to open the "IPsec" screen.

IPsec connection status #

Check IPsec connection status #

Click on the "Status" tab to view the status of the IPsec connection you are connected to.

Check IPsec details #

On the "Status" tab, you can check the status, XFRM state, and XFRM policy by toggling the radio buttons for more information.

IPsec Configuration #

Display a list of IPsec settings #

Switching between the "IKE" and "SA" tabs allows you to check the IPsec settings.

Add IPsec settings #

Add IPsec settings.

Adding IKE Configuration

This is how it is set up when the IKE tab is selected.

 「 IKE 」タブにて[ 新規追加 ]をクリックします。
Enter the following basic information for IKE settings (1) to (7) and click Next.

Select All to allow all addresses.
By checking the Local ID checkbox, you can also select the type and enter the ID.

Select All to allow all addresses.
By checking the Remote ID checkbox, you can also select the type and enter the ID.

Enter the following detailed information about IKE (1) to (6) and click "Next".
*Because this is an optional field, you can proceed to the next step even if you have not entered any information.

Select "No limit" for no limit on the number of retries.

Configure the transform settings and click Next.
*Because this is an optional field, you can proceed to the next step even if you have not entered any information.

Enabling Transform Limit enables operation to be limited to specified transforms only.

Select the encryption algorithm.
Select the authentication algorithm.
Specify PRF (Pseudo-Random Functions). This is valid only for IKEv2.
Select Diffie Hellman Groups.

[Click Next.
Confirm the settings and click [Setup].

IKE configuration is completed.

Adding SA settings

This is how it is set up when the SA tab is selected.

On the "SA" tab, click "New".
Enter the following basic information for SA settings (1) through (12) and click Next.
Configure the transform settings and click Next.
*Because this is an optional field, you can proceed to the next step even if you have not entered any information.

Enabling Transform Limit enables operation to be limited to specified transforms only.

Select the encryption algorithm.
Select the authentication algorithm.
Specify PFS (Perfect Forward Secrecy).

[Click Next.
Confirm the settings and click [Setup].

SA configuration is completed.

Edit IPsec settings #

Edit IPsec settings.
It is possible to edit for IKE and SA respectively. This section uses IKE as an example.

In the "IKE" tab, click the "..." button to the right of the IPsec setting you wish to edit, and select "Edit".

The "Edit IKE Settings" screen appears.

Edit the settings and click [Setup].

The information on the modified IKE settings is updated.

Delete IPsec settings #

There are two ways to delete registered IPsec settings: individually from the IPsec operation menu, or after selecting all IPsec settings to be deleted.
Deletion can be performed for IKE and SA, respectively. This section uses IKE as an example.

Delete IPsec settings individually

This method is to select Delete from the operation menu of IPsec settings.

In the "IKE" tab, click [...] to the right of the IPsec setting you wish to delete and select "Delete" from the menu that appears.
[Click Delete.

IPsec settings are deleted.

Selecting and deleting multiple IPsec settings

This method is used to delete IPsec settings after checking the check boxes of the IPsec settings to be deleted. This is useful for deleting multiple IPsec settings at once, or you can select a single IPsec setting to delete.

On the "IPsec Settings" screen, click the checkbox to the left of the IPsec setting you wish to delete, place a checkmark in the checkbox, and click "Delete".
[Click Delete.

IPsec settings are deleted.

Scroll to Top