beautypg.com

Configuring an ipsec proposal in custom mode – H3C Technologies H3C WX3000E Series Wireless Switches User Manual

Page 876

background image

855

Tunnel-AH-MD5-ESP-3DES—Uses the ESP and AH security protocols successively, making ESP

use the 3DES encryption algorithm and perform no authentication, and making AH use the
MD5 authentication algorithm.

All these suites use the tunnel mode for IP packet encapsulation.

7.

Click Apply.

Configuring an IPsec proposal in custom mode

1.

From the navigation tree, select VPN > IPSec.

2.

Click the Proposal tab.
The IPsec proposal list page as shown in

Figure 629

appears.

3.

Click Add.
The IPsec proposal configuration wizard page as shown in

Figure 630

appears.

4.

Click Custom mode.

Figure 911 IPsec proposal configuration in custom mode

5.

Configure the IPsec proposal parameters, as described in

Table 274

.

6.

Click Apply.

Table 274 Configuration items

Item

Description

Proposal Name

Enter a name for the IPsec proposal.

Encapsulation
Mode

Select an IP packet encapsulation mode for the IPsec proposal. Options include:

Tunnel—Uses the tunnel mode.

Transport—Uses the transport mode.

Security Protocol

Select a security protocol setting for the proposal. Options include:

AH—Uses the AH protocol.

ESP—Uses the ESP protocol.

AH-ESP—Uses ESP first and then AH.

AH Authentication
Algorithm

Select an authentication algorithm for AH when the security protocol setting is AH or
AH-ESP.
Available authentication algorithms include MD5 and SHA1.