ER75s
Continued from previous page
Item
Description
Authenticate Mode
By this parameter can be set authentication:
•
Pre-shared key
– shared key for both off-side tunnel
•
X.509 Certificate
– allows X.509 certification in multiclient
mode
Pre-shared Key
Sharable key for both parties tunnel.
CA Certificate
This certificate is necessary to insert Authentication mode x.509.
Remote Certificate
This certificate is necessary to insert Authentication mode x.509.
Local Certificate
This certificate is necessary to insert Authentication mode x.509.
Local Private Key
This private key is necessary to insert Authentication mode
x.509.
Local Passphrase
This Local Passphrase is necessary to insert Authentication
mode x.509.
Extra Options
Use this parameter to define additional parameters of the IPsec
tunnel, for example secure parameters etc.
Table 41: OpenVPN tunnels configuration
The certificates and private keys have to be in PEM format. As certificate it is possible to
use only certificate which has start and stop tag certificate.
Random time, after which it will re-exchange of new keys are defined:
Lifetime - (Rekey random value in range (from 0 to Rekey margin * Rekey Fuzz/100))
By default, the repeated exchange of keys held in the time range:
•
Minimal time: 1h - (9m + 9m) = 42m
•
Maximal time: 1h - (9m + 0m) = 51m
When setting the times for key exchange is recommended to leave the default setting in
which tunnel has guaranteed security. When set higher time, tunnel has smaller operating
costs and smaller the safety. Conversely, reducing the time, tunnel has higher operating costs
and higher safety of the tunnel.
The changes in settings will apply after pressing the
Apply
button.
64
Summary of Contents for ER75s
Page 1: ...EDGE router ER75s USER MANUAL ...
Page 40: ...ER75s Figure 24 Topology of example LAN configuration 1 32 ...
Page 54: ...ER75s Figure 33 Mobile WAN configuration 46 ...
Page 59: ...ER75s Figure 38 Firewall configuration 51 ...
Page 76: ...ER75s Figure 49 IPsec tunnels configuration 68 ...
Page 78: ...ER75s Figure 53 Topology of GRE tunnel configuration 70 ...