Avaya 4600 IP Phone User Manual


 
VPNremote for 4600 Series IP Telephone Installation and Deployment
Avaya Inc. - Proprietary
Use pursuant to Company Instructions.
6
4. 3DES,HMAC-MD5,DH-2
5. DES,HMAC-SHA1,DH-2
6. DES,HMAC-MD5,DH-2
7. AES-192,HMAC-SHA1,DH-2
8. AES-192,HMAC-MD5,DH-2
9. AES-256,HMAC-SHA1,DH-2
10. AES-256,HMAC-MD5,DH-2
By default VPNremote phone sends following proposal list during phase 2 negotiation
1. ESP,AES-128,HMAC-SHA1,DH-None
2. ESP,AES-128,HMAC-MD5,DH-None
3. ESP,3DES,HMAC-SHA1,DH- None
4. ESP,3DES,HMAC-MD5,DH- None
5. ESP,DES,HMAC-SHA1,DH- None
6. ESP,DES,HMAC-MD5,DH- None
7. ESP,AES-192,HMAC-SHA1,DH- None
8. ESP,AES-192,HMAC-MD5,DH- None
9. ESP,AES-256,HMAC-SHA1,DH- None
10. ESP,AES-256,HMAC-MD5,DH- None
Refer to NVIKEDHGRP, NVPFSDHGRP, NVIKEP1ENCALG, NVIKEP2ENCALG,
NVIKEP1AUTHALG and NVIKEP2AUTHALG system variable description in the
accompanying 46vpnsetting_readme.txt on how to modify the list of proposals sent by
VPNremote phones.
4.1.3 Security Association lifetime
VPNremote always proposes security association life time of 1 day. This value cannot be
modified in the phone; However, if the security gateway is configured to offer a different
life time, the VPNremote phone will accept the life time offered by the SG. It is
recommended that you always configure security gateway with security association life
time of 5 days in order to minimize the complex calculations required by a re-key
transaction.
4.1.4 Avaya proprietary CCD SA lifetime
VPNremote phone uses IKE and IPsec configuration sent by the security gateway. Hence
no special consideration or customization required on VPNremote phones. For Avaya
security gateway it is recommended to use IKE and IPsec SA life time of 8 hours instead
of 5 days as recommended for non-Avaya security gateways.
3.2 Client IP Address Pool – All SGs
The client IP address pool is the IP address range configured on the security gateway for
IPsec clients. VPNremote phone uses an address from the pool as its address for
communicating with hosts on the private side of the security gateway. Size of the Client
IP Address Pool determines the maximum number of IPsec clients that can connect to the
security gateway at any time. Limit the size of client IP address pool to restrict the