SunScreen 3.2 Administration Guide

IPsec Key

The IPsec Key (also referenced as manual keying) dialog allows you to generate an IPsec key by either manually typing the key value or to use a random number generator to generate the key. The key that is generated by the random number generator is determined by the algorithm used.


Note -

IPsec Key cannot be used for remote administration or VPN.


To Add an IPsec Key
  1. Execute the steps in "To Modify the Policies Associated with a Common Object".

  2. Select IPsec Key from the Type list.

    Graphic
  3. Select NEW from the Add New Object list.

    The IPsec Key dialog appears.

    Graphic
  4. Type the name for the IPsec key in the Name field.

  5. (Optional) Type a brief description for the IPsec key.

  6. Select which Screen recognizes the IPsec key. The default is all.


    Note -

    Typing a Screen name allows you to define packet filter rules that encrypt traffic between any two machines, not just between an Administration Station and a Screen.


  7. Select the Key size. The Hex string values you can select are:

    DES-CBC

    16

    3DES-CBC

    48

    MD5

    32

    SHA1

    40

  8. Manually type a key value to be used for the IPsec key. You should use the above hex values for proper security. If you type additional hex characters, they are discarded and the maximum value listed above is used.

  9. Alternatively, click the Generate New Key to use the random generator to create the IPsec key.

  10. Click the OK button