
E-5
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Appendix E Supported VPN Standards and Security Proposals
Supported Easy VPN Proposals
Table E-2 lists the Phase 2 security proposals supported by Easy VPN clients.
Ta b l e E-2 Easy VPN Client Phase 2 Proposals
AES256
1. PIX Firewall does not support IP compression.
MD5
1
AES256 SHA
AES128 MD5
AES128 SHA
AES256 MD5
AES256 SHA
AES128 MD5
AES128 SHA
3DES MD5
3DES SHA
3DES MD5
3DES SHA
DES MD5
DES MD5
NULL MD5
NULL SHA
IKE-DES-MD5-RSA-DH1 RSA Digital Certificate MD5/HMAC-128 DES-56 Group 1 (768 bits)
IKE-3DES-MD5-RSA-DH5 RSA Digital Certificate MD5/HMAC-128 3DES-168 Group 5 (1536 bits)
IKE-3DES-SHA-RSA-DH5 RSA Digital Certificate SHA/HMAC-160 3DES-168 Group 5 (1536 bits)
IKE-AES128-MD5-RSA-DH5 RSA Digital Certificate MD5/HMAC-128 AES-128 Group 5 (1536 bits)
IKE-AES128-SHA-RSA-DH5 RSA Digital Certificate SHA/HMAC-160 AES-128 Group 5 (1536 bits)
IKE-AES192-MD5-RSA-DH5 RSA Digital Certificate MD5/HMAC-128 AES-192 Group 5 (1536 bits)
IKE-AES192-SHA-RSA-DH5 RSA Digital Certificate SHA/HMAC-160 AES-192 Group 5 (1536 bits)
IKE-AES256-MD5-RSA-DH5 RSA Digital Certificate MD5/HMAC-128 AES-256 Group 5 (1536 bits)
IKE-AES256-SHA-RSA-DH5 RSA Digital Certificate SHA/HMAC-160 AES-256 Group 5 (1536 bits)
Table E-1 Easy VPN Client IKE (Phase 1) Proposals (continued)
Proposal Name Authentication Mode
Authentication
Algorithm
Encryption
Algorithm
Diffie- Hellman
Group
Comentarios a estos manuales