DRO-210i Web Configuration
DRO-210i User Manual Page 3-39
IKE Encryption
- This drop-down menu allows user to select the
encryption algorithm that will be used to encrypt the messages passed
between the VPN tunnel endpoints during the Phase 1 negotiation. User
can choose between DES and 3DES encryption methods. The key length
for the 3DES algorithm is three times as long as the DES key, and is
therefore more likely to be secure. User must choose exactly the same IKE
Encryption algorithm on both ends of a VPN tunnel.
Phase 2 Proposal
PFS Mode
- This drop-down menu allows user to specify the mode that
will be used for IPSec Perfect Forward Secrecy (PFS). The choices are
Disabled, Group 1, and Group 2. Group 1 uses 768-bit prime number,
,Group 2 uses 1024-bit prime number and Disable disables the PFS mode.
User must use exactly the same PFS mode on both ends of the VPN
tunnel.
IPSec Operation
- This drop-down menu allows user to select the IPSec
transform, that will be applied to packets that are sent between the two
endpoints of a VPN tunnel. ESP - specifies that the entire packet will be
encrypted (by the DES,3DES or AES algorithm, as selected in ESP
Transform field) and authenticated (by the MD5 or SHA algorithm, as
selected in ESP Authentication field). AH - specifies that only the
authentication algorithm (MD5 or SHA, as selected below) will be used.
When AH is selected, the data portion of packets sent between the two
endpoints of a VPN tunnel will not be encrypted.
IPsec Life Duration
- Similar as IKE Life Duration, it is used for life
duration of phase 2 key (in seconds). When it is expired,
the two peers should trigger phase 2 negotiation again to set up a new
phase 2 key.
ESP Transform
- This drop-down menu allows user to select the
encryption algorithm that will be used when ESP is selected in the IPSec
Operation drop-down menu above. User can choose between Null - no
encryption, DES - using DES encryption, 3DES - using triple DES
encryption and AES - using AES encryption. User must select the same
ESP transform (encryption algorithm) on both ends of a VPN tunnel.