Setting a Computer

Set IPSec to a computer.

Follow the procedure below, and be sure to perform all the steps in order.

Memo

Set this machine before setting the computer.

Setting This Machine

  1. Click [Start], and then select [Control Panel] > [System and Security] > [Administrative Tools].

  2. Double-click [Local Security Policy].

  3. Click [IP Security Policies on Local Computer] in the [Local Security Policy] window.

  4. Select [Create IP Security Policy] from the [Action] menu.

  5. Click [Next] in [IP Security Policy Wizard].

  6. Enter [Name] and [Description], and then click [Next].

  7. Clear the [Activate the default response rule (earlier versions of Windows only)] check box, and then click [Next].

  8. Select the [Edit Properties] check box, and then click [Finish].

  1. Select the [General] tab in the New IP Security Policy Properties window.

  2. Click [Settings].

  3. Enter a value (minutes) in [Authenticate and generate a new key after every] in the [Key Exchange Settings] window.

    Note

    Specify the same value as [Lifetime] in the "Phase1 Proposal" setting in "Setting This Machine". Enter a value in minutes in this step even if [Lifetime] is specified in seconds.

  4. Click [Methods].

  5. Click [Add] in the [Key Exchange Security Methods] window.

  6. Specify [Integrity algorithm], [Encryption algorithm], and [Diffie-Hellman group].

    Note

    Select the same value specified in [IKE Encryption Algorithm], [IKE Hush Algorithm], and [Diffie-Hellman group] in the "Phase1 Proposal" setting in "Setting This Machine".

  7. Click [OK].

  8. Select [OK] in the [Key Exchange Security Methods] window.

  9. Click [OK] in the [Key Exchange Settings] window.

  1. Select the [Rules] tab in the IP security policy properties window.

  2. Click [Add].

  3. Click [Next] in [Security Rule Wizard].

  4. Select [This rule does not specify a tunnel] on the [Tunnel Endpoint] screen, and then click [Next].

  5. Select [All Network Connections] on the [Network Type] screen, and then click [Next].

  6. Click [Add] on the [IP Filter List] screen.

  7. Click [Add] in the [IP Filter List] window.

  8. Click [Next] on [IP Filter Wizard].

  9. Click [Next] on the [IP Filter Description and Mirrored property] screen.

  10. Click [Next] on the [IP Traffic Source] screen.

  11. Click [Next] on the [IP Traffic Destination] screen.

  12. Click [Next] on the [IP Protocol Type] screen.

  13. Click [Finish].

  1. Click [OK] in the [IP Filter List] window.

  2. Select a new IP filter from the list on the [Security Rule Wizard], and then click [Next].

  3. Click [Add] on the [Filter Action] screen.

  4. Click [Next] in the [Filter Action Wizard].

  5. Enter [Name] and [Description] on the [Filter Action Name] screen.

  6. Select [Negotiate security] on the [Filter Action General Options] screen, and then click [Next].

  7. Select [Do not allow unsecured communication] on the [Communicating with computers that do not support IPsec] screen, and then click [Next].

  8. Select [Custom] on the [IP Traffic Security] screen, and then click [Settings].

  9. Set in the [Custom Security Method Settings] window, and then click [OK].

    Note

    Set the same values as those specified in [ESP Encryption Algorithm], [ESP Authentication Algorithm], [AH Authentication Algorithm], and [LifeTime] in the "Phase2 Proposal" setting in "Setting This Machine".

  10. Click [Next] on the [IP Traffic Security] screen.

  11. Select the [Edit Properties] check box, and then click [Finish].

  1. If you want to enable Key PFS, select the [Use session key perfect forward secrecy (PFS)] check box in the [Filter Action Properties] window.

  2. If you perform IPSec communication with the IPv6 global address, select the [Accept unsecured communication, but always respond using IPsec] check box.

  3. Click [OK].

  4. Select the new filter action, and then click [Next].

  5. Select the authentication method on the [Authentication Method] screen, and then click [Next].

    Note

    If the pre-shared key is set in "Setting This Machine", enable "Use this string to protect the key exchange (preshared key)" on the [Authentication Method] screen and enter the pre-shared key.

  6. Click [Finish].

  7. Click [OK] in the New IP Security Policy Properties window.

  8. Select the new IP security policy in the [Local Security Policy] window.

  9. Select [Assign] from the [Action] menu.

  10. Check that [Yes] is displayed for [Policy Assigned] for the new IP security policy.

  11. Click [x] in the [Local Security Policy] window.