IPSec Settings |
For information on the optional products required to use this function, see "Optional Products Required for Each Function (imageRUNNER ADVANCE C9075 PRO/C9065 PRO)" or "Optional Products Required for Each Function (imageRUNNER ADVANCE C7065/C7055)." IPSec is a protocol for ensuring the security of IP packets sent and received over an IP network by protecting it from threats such as theft, modification, and impersonation. IPSec is applied for TCP packets, UDP (User Datagram Protocol) packets, and ICMP (Internet Control Message Protocol) packets. The reason why IPSec is superior to other security protocols is that since it adds security functions to IP, the basic protocol of the internet, it does not depend on the application software and network configuration. This section describes the procedure for creating a security policy to set IPSec communications, using the control panel of the machine. A security policy registers the settings for IPSec, such as the packets to process with IPSec, and the algorithm to use for authentication and encryption. A logical connection established for traffic by conducting negotiations according to an IPSec security policy is called an IPSec SA (Security Association). The features of the IPSec used by the machine are as follows. |
Since the IPSec of the machine only supports the transport mode, authentication and encryption is only applied to the data part of the IP packets.
At least one of the following methods must be set for the machine. You cannot set both methods at the same time.
Supports IKEv1 (Internet Key Exchange version 1) for exchanging keys based on ISAKMP (Internet Security Association and Key Management Protocol). IKE includes two phases; in phase 1 the SA used for IKE (IKE SA) is created, and in phase 2 the SA used for IPSec (IPSec SA) is created. To set authentication with the pre-shared key method, it is necessary to decide upon a pre-shared key in advance, which is a keyword (24 characters or less) used for both devices to send and receive data. Use the control panel of the machine to set the same pre-shared key as the destination to perform IPSec communications with, and perform authentication with the pre-shared key method. To select authentication with a digital signature, a CA certificate (X.509 certificate) must be registered for bilateral authentication of the IPSec destination. For information on installing the CA certificate using the Remote UI, see "Remote UI." For information on registering the installed CA certificate file, see "Registering a CA Certificate File Installed from a Computer." The types of key pair and certificate that can be used for authentication with the digital signature method are indicated below.
|
Remark |
|
||||||
Registering a Security Policy |
Editing a Security Policy |