DRO-210i Web Configuration
DRO-210i User Manual Page 3-42
Tunnel Source Interface
- The WAN interface which serves as the
tunnel's source endpoint.
Shared Key
- The secret key that should be entered exactly the same way
on both endpoints in order to establish Phase I negotiation. The purpose of
this key is for the IPSec peers to authenticate each other.
Tunnel Type
- This drop-down menu allows to select the type of VPN
Tunnel user is configuring. User can choose between Public and Private .
At the time of the writing this manual, only Public IPSec VPN tunnels are
supported.
Phase 1 Proposal
Mode
- This will allow a user to select the phase 1 negotiation mode. User
can select between Main and Aggressive modes. In the Main mode, all
communications between the two endpoints of an IPSec VPN tunnel are
encrypted. In Aggressive mode, there is no encryption in the Phase 1
negotiation.
DH Group
- The DH algorithm allows the router to generate shared keys
in a secure manner. This shared key is used for deriving encryption and
hash algorithm keys used during Phase 1 negotiation. Group 1 generates a
768-bit key and Group 2 generates a 1024-bit key. The same DH Group
must be used on both ends of an IPSec VPN tunnel.
IKE Life Duration
- This is the life duration of phase 1 key (in seconds).
When it is expired, the two IPSec peers should trigger phase 1 negotiation
again to set up a fresh IPSec tunnel.
IKE Hash
- This drop-down menu allows the user to select the algorithm
that will be used to ensure that the messages exchanged between the two
IPSec VPN tunnel endpoints has been received exactly as it was sent. In
other words, a Hash algorithm is used to generate a binary number by a
mathematical operation using the entire message. The resulting number is
called a message digest. The very same mathematical operation is
performed when the message is received, and if there has been any change
in the message during transit, the resulting message digest number will be
different and the message will be rejected. User can choose between MD5