DVG-N5402G/ACF
Wireless AC1200 Dual Band Gigabit Router
with Fiber WAN Port, 3G/LTE Support, 2 FXS Ports, 1 PSTN
(lifeline) Port, and USB Port
User Manual
Configuring via Web-based Interface
Parameter
Description
First phase DHgroup
type
A Diffie-Hellman key group for Phase 1. Select a value from the drop-
down list.
IKE-SA lifetime
The lifetime of IKE-SA keys in seconds. After the specified period it is
required to renegotiate the keys. The value specified in this field
should exceed the value specified in the
IPsec-SA lifetime
field.
Specify
0
if you don't want to limit the lifetime of the keys.
The second phase
Second phase
encryption algorithm
Select encryption algorithm from the drop-down list.
Authentication
algorithm
Select authentication algorithm from the drop-down list.
Enable PFS
Select the checkbox to enable the PFS option (
Perfect Forward
Secrecy
). If the checkbox is selected, a new encryption key exchange
will be used for Phase 2. This option increases the security level of
data transfer.
Second phase
PFSgroup type
A Diffie-Hellman key group for Phase 2. Select a value from the drop-
down list. The field is available, if the
Enable PFS
checkbox is
selected.
IPsec-SA lifetime
The lifetime of IPsec-SA keys in seconds. After the specified period it
is required to renegotiate the keys. Specify
0
if you don't want to limit
the lifetime of the keys.
If you need to specify IP addresses of local and remote subnets for creating a tunnel, click the
Add
button in the
Tunneled networks
section.
Figure 145. The page for adding an IPsec tunnel. The
Tunneled networks
section.
In the line displayed, you can specify the following parameters:
Parameter
Description
Local subnet
A local subnet IP address and mask.
Remote subnet
A remote subnet IP address and mask.
Page
192
of 259