Instruction manual

Section 4, User Interface Guide NetVanta 2000 Series System Manual
70 © 2002 ADTRAN, Inc. 61200361L1-1E
L
OCAL
ID T
YPE
-- Select any one of the options available in the drop down menu. It includes IP A
DDRESS
(IP v.4 address),
FQDN (fully qualified domain name), U
SER
FQDN (fully qualified username string) and
DER ANS1 DN (X.500 distinguished name).
L
OCAL
ID D
ATA
-- Based on the L
OCAL
ID T
YPE
selected, enter the appropriate Local ID data. If IP A
DDRESS
is selected, enter an IP v.4 address in the
L
OCAL
ID D
ATA
field. If FQDN is selected, enter a fully qualified
domain name (i.e. netvanta1.adtran.com) in the
L
OCAL
ID D
ATA
field. If U
SER
FQDN is selected, enter a
fully qualified username string (i.e. networkmaster@adtran.com) in the
L
OCAL
ID D
ATA
field. If DER
ANS1 DN
is selected, enter the X.500 Distinguished name (X.501) of the principal whose certificates are
being exchanged to establish the SA in the
L
OCAL
ID D
ATA
field.
Remote ID Type -- Select any one of the options available in the drop down menu. It includes IP Address
(IP v.4 address), FQDN (fully qualified domain name), User FQDN (fully qualified username string) and
DER ANS1 DN (X.500 distinguished name).
R
EMOTE
ID D
ATA
- Based on the R
EMOTE
ID T
YPE
selected, enter the appropriate Local ID data. If IP
A
DDRESS
is selected, enter an IP v.4 address in the R
EMOTE
ID D
ATA
field. If FQDN is selected, enter a fully
qualified domain name (i.e. advanta.adtran.com) in the
R
EMOTE
ID D
ATA
field. If U
SER
FQDN is selected,
enter a fully qualified username string (i.e. networkmaster@adtran.com) in the
R
EMOTE
ID D
ATA
field. If
DER ANS1 DN is selected, enter the X.500 Distinguished name (X.501) of the principal whose certificates
are being exchanged to establish the SA in the
R
EMOTE
ID D
ATA
field.You can specify up to 10 R
EMOTE
ID
T
YPES
and R
EMOTE
ID D
ATA
.
L
OCAL
IP A
DDRESS
- You MUST specify the Local IP address of the system.
R
EMOTE
IP A
DDRESS
- You must specify the Remote IP address.
E
NCRYPTION
A
LGORITHM
- You may select one of the algorithms specified in the drop down menu. It
includes DES and 3DES.
A
UTHENTICATION
A
LGORITHM
- You may select one of the algorithms specified in the drop down menu. It
includes MD5 and SHA1.
A
UTHENTICATION
M
ODE
- You may select any one of the authentication modes specified in the drop down
menu. This includes Pre-Shared Key, DSS_SIGN, RSA_SIGN, RSA_ENC, RSA_REV_ENC.
K
EY
- If you select Pre-Shared key as your authentication mechanism, you must specify the key. This
depends on the Authentication algorithm which you have selected. If you have selected the MD5 algorithm
then the key length should be 16 bytes. If it is SHA1, the key length should be 20 bytes.
L
IFE
TIME
-Lifetime in seconds of the IKE SA.
DH G
ROUP
- There are two groups to choose from in the drop down menu. You may have to choose one of
them.
Submit with these changes and this will be stored in the memory.