Billion 810VGTX Router
Page | 88
Perfect Forward Secrecy: Choose whether to enable PFS using Diffie-Hellman public-key cryptography to change
encryption keys during the second phase of VPN negotiation. This function will provide better security, but extends the
VPN negotiation time. Diffie-Hellman is a public-key cryptography protocol that allows two parties to establish a shared
secret over an unsecured communication channel (i.e. over the Internet). There are three modes, MODP 768-bit, MODP
1024-bit and MODP 1536-bit. MODP stands for Modular Exponentiation Groups.
Pre-shared Key: This is for the Internet Key Exchange (IKE) protocol, a string from 4 to 128 characters. Both sides
should use the same key. IKE is used to establish a shared security policy and authenticated keys for services (such
as IPSec) that require a key. Before any IPSec traffic can be passed, each router must be able to verify the identity of
its peer. This can be done by manually entering the pre-shared key into both sides (router or hosts).
Click Edit/Delete to save your changes.
Example: Configuring a L2TP VPN - Remote Access Dial-in Connection
A remote worker establishes a L2TP VPN connection with head office using Microsoft's VPN Adapter (included with
Windows XP/2000/ME, etc.). The router is installed in the head office, connected to a couple of PCs and Servers.