VPN
Site-to-Site IPsec VPN
Cisco RV132W ADSL2+ Wireless-N and RV134W VDSL2 Wireless-AC VPN Router Administration Guide
105
6
STEP 5
In the
IKE SA Parameters
section, configure parameters to define the strength
and mode for negotiating Security Association (SA) between your device and the
remote router:
a. In the
Encryption Algorithm
field, choose the algorithm to encrypt data.
b. In the
Authentication Algorithm
field, specify the authentication algorithm for
the VPN header. Ensure that the authentication algorithm is configured
identically on both sides of the VPN tunnel.
•
In the Authentication Method field, select one of the following options:
•
Pre-Shared Key: the VPN peers use a pre-shared key to authenticate each
other.
•
Certificate: the VPN peers use a certificate to authenticate each other. When
the Authentication Method is Certificate:
-
The Local/Remote Identifier can be set to “DER ASN1 DN” with the value
of the Distinguished Name of the certificate.
-
The Local/Remote Identifier can also be set to one of Local WAN IP,
FQDN, USER FQDN, as long as the SubjectAltName of the certificate has
the same type/value as the Identifier. That also means if the CSR of the
certificate is generated by the device (under the menu VPN > Site-to-Site
IPSec VPN > Certificate Management > Generate CSR), the “IP Address”,
“Domain Name”, or “Email Address” should be filled with the correct
value.
c. In the
Diffie-Hellman (DH) Group
field, specify the DH Group algorithm used
when exchanging a pre-shared key. The DH Group sets the strength of the
algorithm in bits. Ensure that the DH Group is configured identically on both
sides of the IKE policy.
d. In the
SA-Lifetime
field, enter the interval, in seconds, after which the Security
Association becomes invalid.
e. To enable the
Dead Peer Detection
feature, check the
Enable
box. Dead Peer
Detection (DPD) is used to detect if the peer is alive. If the peer is detected as
dead, the device deletes the IPsec and IKE Security Association. If you enable
this feature, also enter these settings:
•
DPD Delay
—The interval, in seconds, between consecutive DPD R-U-
THERE messages. DPD R-U-THERE messages are sent at every interval.
•
Failure Count
—This field shows the number of failure counts. The default
setting is 3. The device will consider the peer is dead if it does not receive
DPD response from the peer for this number of times.