SnapGear 2.0.1 User Manual

Page 132

Advertising
background image

Virtual Private Networking

128

TCGID

[Siemens] Trust Center Global ID

The attribute/value pairs must be of the form attribute=value and be separated by
commas. For example : C=US, ST=Illinois, L=Chicago, O=CyberGuard,
OU=Sales, CN=SG550. It must match exactly the Distinguished Name of the
remote party's local certificate to successfully authenticate the tunnel. This field
appears when x.509 Certificates has been selected.

Generate an RSA key of pull down menu allows the length of the CyberGuard

SG appliance generated RSA public/private key pair to be specified. The options
include 512, 1024, 1536 and 2048 bits. The greater the key pair length, the
longer the time required to generate the keys. It may take up to 20 minutes for a
2048 bit RSA key to be generated. This option appears when RSA Digital Key
Signatures has been selected.

SPI Number field is the Security Parameters Index. However, this applies to the

remote party. It is a hexadecimal value and must be unique. It is used to
establish and uniquely identify the tunnel. It must be of the form 0xhex, where
hex is one or more hexadecimal digits and be in the range of 0x100-0xfff. This
field appears when Manual Keying has been selected.

Authentication Key field is the ESP Authentication Key. However, this applies to

the remote party. It must be of the form 0xhex, where hex is one or more
hexadecimal digits. The hex part must be exactly 32 characters long when using
MD5 or 40 characters long when using SHA1 (excluding any underscore
characters). It must use the same hash as the CyberGuard SG appliance's
authentication key. This field appears when Manual Keying has been selected.

Encryption Key field is the ESP Encryption Key. However, this applies to the

remote party. It must be of the form 0xhex, where hex is one or more
hexadecimal digits. The hex part must be exactly 16 characters long when using
DES or 48 characters long when using 3DES (excluding any underscore
characters). It must use the same cipher as the CyberGuard SG appliance's
encryption key. This field appears when Manual Keying has been selected.

Remote Network is the network behind the remote party. This field appears

when Manual Keying has been selected.

Advertising