last update Sep. 26, 2007
|
parameter |
BASIC |
ADVANCED |
|||
|
Exchange type |
Phase-1 |
Main mode |
Aggressive mode |
||
|
Phase-2 |
Quick mode |
- |
|||
|
ISAKMP SA |
Encryption Algorithm *1 |
3DES-CBC |
DES-CBC, AES-CBC (128bit) |
||
|
Hash Algorithm |
SHA1 |
MD5 |
|||
|
Authentication Method |
Pre-shared key |
Digital Signature (RSA) |
|||
|
Diffie-Hellman Group |
2 |
1,5,14 |
|||
|
Life Type |
Seconds |
- |
|||
|
IPsec SA |
Encapsulation mode |
End-Node |
Transport |
Tunnel |
|
|
SGW |
Tunnel |
- |
|||
|
Security Protocol |
ESP with Authentication |
ESP |
|||
|
Encryption Algorithm |
3DES-CBC |
DES-CBC ,AES-CBC (128bit), ESP-NULL |
|||
|
Hash Algorithm |
HMAC-SHA1 |
HMAC-MD5
, |
|||
|
Life Type |
Seconds |
- |
|||
|
IKE Phase-1 |
Sending multiple proposal |
- |
Support |
||
|
IKE Phase-2 |
PFS |
- |
Support |
||
|
Commit bit |
- |
Support |
|||
|
Re-key |
Support |
- |
|||
|
Sending multiple proposal |
- |
Support |
|||
|
IPsec Transmission |
Encapsulation mode |
End-Node |
Transport |
Tunnel |
|
|
SGW |
Tunnel |
- |
|||
|
Security Protocol |
ESP with Authentication |
ESP |
|||
|
Encryption Algorithm |
3DES-CBC |
DES-CBC ,AES-CBC (128bit), ESP-NULL |
|||
|
Hash Algorithm |
HMAC-SHA1 |
HMAC-MD5
, |
|||
|
Anti-replay |
Sender |
Receiver |
|||
If you select Aggressive as Phase-1 exchange mode,
then you need to refer the following test specfications.
If you select Aggressive as Phase-1 exchange mode,
then you need to refer the following test specfications.
FreeBSD 5.4-RELEASE w/ipsec-tools-0.6.5_1(patched ipsec-tools-0.6.5-ipv6.patch) (Main mode)
FreeBSD 5.4-RELEASE w/ipsec-tools-0.6.5_1(patched ipsec-tools-0.6.5-ipv6.patch) (Aggressive mode)
FreeBSD 5.4-RELEASE w/ racoon-20040818a_1 (Main mode)
FreeBSD 5.4-RELEASE w/ racoon-20040818a_1 (Aggressive mode)
IPv6 Forum, IPv6 Logo Comittee