Select
Enable perfect forward secrecy (PFS)
to improve the security of Phase 2
keys. See
About perfect forward secrecy (PFS)
.
Select
Specify the
Keylife
for Phase 2. The keylife is the amount of time in seconds before
the phase 2 encryption key expires. When the key expires, a new key is generated
without interrupting service.
600
Specify the IKE
Identity
(also called the proxy ID) to use for the tunnel. The identity
labels all IPSec packets associated with a specific tunnel so that the VPN gateway
can associate IPSec packets that it receives with the correct tunnel. The default
identity is IP Subnet, which means the IPSec packets associated with this tunnel are
identified using the subnet IP address. You can also set Identity to IP address.
IP Subnet
Authentication
Key
Enter up to 20 characters. The VPN gateway and clients must have the same key and
it should only be known by network administrators.
ddcHH01887d
Incoming NAT
Select Incoming NAT if you require Network address translation for VPN packets.
Select
Complete the following procedure on the DFL-500 dial-up VPN gateway:
·
Go to
VPN > IPSEC > Autokey IKE
.
·
Select New to add a new Autokey IKE VPN tunnel.
·
Enter the VPN Tunnel Name, Remote Gateway, Keylife, and Authentication Key.
·
Select the P1 Proposal and the P2 Proposal algorithms.
·
Select OK to save the Autokey IKE VPN tunnel.
Configuring remote IPSec VPN clients
The remote VPN clients must be running industry standard IPSec Autokey IKE VPN client software. D-Link
recommends the SafeNet/Soft-PK client from IRE, Inc.
Configure the client as required to connect to the dial-up VPN gateway using an IPSec VPN configuration.
Make sure the client configuration includes the settings in
Remote IPSec VPN client configuration
Remote IPSec VPN client configuration
Description
Example
Setting
Tunnel Name
Should correspond to the dial-up VPN tunnel name used on the DFL-500 dial-up
VPN gateway.
Dial-up_VPN
Remote Gateway
The External IP address of the dial-up VPN gateway.
1.1.1.1
Authentication
Key
The client authentication key should match the dial-up VPN gateway tunnel
authentication key.
ddcHH01887d
Configuring remote IPSec VPN gateways
The remote IPSec VPN gateways must be DFL-500 IPSec VPN gateways or third-party IPSec VPN gateways
running industry standard IPSec Autokey IKE VPN software.
Configure the VPN gateway as required to connect to the dial-up VPN gateway using an IPSec VPN
configuration. Make sure the gateway configuration includes the settings in
.
Remote IPSec VPN gateway configuration
Description
Example
Setting
Tunnel Name
Should correspond to the dial-up VPN tunnel name used on the DFL-500
Dial-up_VPN
DFL-500 User Manual
65