ATM_ID: 60AE1532-693F-11F0-90F0-C4D1B6ACCDE0 MFF: PLANNEDTIMESTAFF: ID: Not_to_use_for_any_Dashboard/CCC/165408 TESTCASE_HEADLINE: IPSEC_FMT_DH_GROUP_19 GROUP: FEATURE: SUB_FEATURE: INPUT:
Important: Please refer the document named 'How to Set up IPsec on Windows 10 for DH Group 19 (EC P-256) .
PROCEDURE:1 Execute CO_AUTH_WEBUI_AUTHENTICATE_SA.2 Select [Security] followed by [IPsec] from the Properties Menu on the left side of the page.3 Click [Actions] to navigate to the IP Actions page. Then click [Add New Action] button.4 Enter the following information,when done click [Next].
Name = ”Require Preshared Key 1”
Description = N/A
Keying Method = Internet Key Exchange (IKEv1)
Pre-shared Key Passphrase = ”ObsidianOrder1”
5 Select the following options then click [Save]. (Click [OK] to respond to the settings confirmation pop-up which follows).
IKE Phase 1 Settings:
Key Lifetime = 86400 Seconds
IKE Phase 2 Settings:
IPsec Mode = Transport Mode
IPsec Security = ESP
Perfect Forward Secrecy = DH Group 19 (EC P-256)
Hash = SHA-256
Encryption = AES-CBC-128/256
Key Lifetime = 28800 Seconds
6 Click [Host Groups] to display the IP Host Groups page. Then click [Add New Host Group]7 Enter the following information,when done click [Save]. (Click [OK] to respond to the settings confirmation pop-up which follows)
Name = “Windows 10 Client”
Description = N/A
Set the following address options:
Ipv4
Address type = Specific
IP Address = 172.16.0.102
8 Click [Security Policies] to navigate to the IPsec Policies page.9 Create a new policy. Set the following options then click [Add Policy]. (Click [OK] to respond to the settings confirmation popup which follows)
Host Groups = Windows 10 Client
Protocol Groups = All
Action = Require Preshared Key 1
10 At Windows 10 Workstation,enable the Firewall and the IPsec Policy rule created. Important: Please refer the Document 'How to Set up IPsec on Windows 10 for DH Group 19 (EC P-256) .11 Test protocol connectivity. From the Windows workstation execute the following commands:
LPR -S 172.16.0.10 -P lp <location of 16MPS.ps>
12 Retrieve Audit log. Execute CO_AUDIT_DOWNLOAD.13 Now disable Windows Firewall and the IPsec Policy rule on Windows 10 workstation.
See CO_AUTH_WEBUI_AUTHENTICATE_SA.The {WEBUI IPSEC PAGE} will be displayed.The {WEBUI IPSEC Add New Action Step 1 of 2 page} will be displayed.The {WEBUI IPSEC Add New Action Step 2 of 2 page} will be displayed.1. The {WEBUI IPSEC PAGE} will be displayed.