beautypg.com

Canon VB-H41 User Manual

Page 71

background image

[IPsec] Setting IPsec

71

5

S

et

ting P

age

(8) [IKE Pre-Shared Key]

Enter the pre-shared key for IKE (auto key exchange)

(up to 127 characters).

Note

If auto key exchange is used, it will take approximately 5 to 10

seconds before communication with the camera starts.

IPsec Set (Manual)

IPsec Sets 1 to 5 are available, and you can specify IPsec

settings for one communication device for each IPsec Set.

(1) [IPsec Set]

Set IPsec Set to [Disable], [Enable in IPv4] or [Enable

in IPv6].

(2) [IPsec Mode]

Set IPsec mode to [Tunnel Mode] or [Transport

Mode].

(3) [Destination IPv4 Address], [Destination IPv6 Address]

Enter the IP address of the connection destination.

(4) [Source IPv4 Address], [Source IPv6 Address]

Enter the IP address of the source.

(5) [Security Protocol]

Set the IPsec protocol to [ESP], [AH] or [ESP and AH].

If [ESP] is selected, enter only the setting items

relating to ESP.

If [AH] is selected, enter only the setting items relating

to AH.

If [ESP and AH] is selected, enter all setting items.

(6) [Security Gateway IPv4 Address], [Security Gateway

IPv6 Address]
If [IPsec Mode] is set to [Tunnel Mode] in (2), set the

IP address of the security gateway.

(7) [Destination Subnet Mask Length] (IPv4), [Destination

Prefix Length] (IPv6)

This setting is required only if [IPsec Mode] is set to

[Tunnel Mode] in (2).

If IPv6 is used, enter a desired prefix length for the

connection destination in the range of 16 to 128.

If IPv4 is used, enter a desired length in the range of 1

to 32.

z

If [Security Protocol] is set to [ESP] or [ESP and AH] in
(5), (8) [SA ESP Encryption Algorithm] to (15) [SA ESP
SPI (inbound)] must be set.

(8) [SA ESP Encryption Algorithm]

Set the ESP encryption algorithm to [AES], [3DES],

[DES] or [NULL] according to the encryption

algorithm supported by the device to connect to.

Normally [AES] or [3DES] is recommended.

(9) [SA ESP Authentication Algorithm]

Set the ESP authentication algorithm to

[HMAC_SHA1_96], [HMAC_MD5_96] or [No

Authentication] according to the authentication

algorithm supported by the device to connect to.

If [ESP] is used alone, [No Authentication] cannot be

selected.

(10)[SA ESP Encryption Key (outbound)]

Set the SA encryption key for outbound. If [AES],

[3DES] or [DES] was selected in (8), set a 128-bit,

192-bit or 64-bit hexadecimal, respectively. This item

need not be set if [NULL] was selected.

(11)[SA ESP Authentication Key (outbound)]

Set the SA authentication key for outbound. If

[HMAC_SHA1_96] or [HMAC_MD5_96] was selected

in (9), set a 160-bit or 128-bit hexadecimal,

respectively. This item need not be set if [No

Authentication] was selected.

(12)[SA ESP SPI (outbound)]

Set the SA SPI value for outbound.

Set a desired value in the range of 256 to

4294967295.

(13)[SA ESP Encryption Key (inbound)]

Set the SA encryption key for inbound.

If [AES], [3DES] or [DES] was selected in (8), set a

128-bit, 192-bit or 64-bit hexadecimal, respectively.

This item need not be set if [NULL] was selected.

(14)[SA ESP Authentication Key (inbound)]

Set the SA authentication key for inbound.

If [HMAC_SHA1_96] or [HMAC_MD5_96] was

selected in (9), set a 160-bit or 128-bit hexadecimal,

respectively. This item need not be set if [No

Authentication] was selected.

(15)[SA ESP SPI (inbound)]

Set the SA SPI value for inbound.

Set a desired value in the range of 256 to

4294967295. Since this setting is used as an ID for

Important

If the camera is rebooted during auto key exchange
communication, a connection error may result after rebooting.

In this case, connect again.

This manual is related to the following products: