
IPSec
System Administrator’s Guide
85
Tunnel settings page
1
Fill in the
Tunnel name
field with an apt description of the tunnel. The name
must not contain spaces or start with a number. For this example, enter:
Branch_Office
2. Select
Enable this tunnel
.
3. Select the Internet interface the IPSec tunnel is to go out on. For this example,
select
default gateway interface
option.
4. Select the type of keying the tunnel will use. For this example, select the
Aggressive mode with Automatic Keying (IKE)
option. This is required when
dynamic addressing is used.
5. Select the type of IPSec endpoint the remote party has. For this example, select
the
dynamic IP address
option.
6. Select the type of authentication the tunnel will use. For this example, select the
Preshared Secret option.
7. Select the type of private network that is behind the Shiva VPN Gateway. For this
example the Headquarters has a single network, so select the
single network
behind this Shiva Gateway
option.
8. Select whether the remote party is a single host or whether it is a gateway that
has a single or has multiple networks behind it. For this example the Branch
Office has single network, so select the
single network behind a gateway
option.
9. Select the type of routing the tunnel will be used as. For this example, select the
be a route to the remote party
option.
10. Click the
Continue
button to configure the Local Endpoint Settings.
Define local endpoint settings
1
Leave the Optional Endpoint ID field blank For this example. It is optional
because the Shiva VPN Gateway has a static IP address. If the remote party is a
Shiva VPN Gateway and an Endpoint ID is used, it must have the form
abcd@efgh.
2. Leave the Enable IP Payload Compression checkbox unchecked.
3. Leave the Enable Phase 1 & 2 rekeying to be initiated from my end checkbox
checked.
4. Click the Continue button to configure the Remote Endpoint Settings.
Define remote endpoint settings
1
Enter the Required Endpoint ID of the remote party. For this example, enter the
Local Endpoint ID at the Branch Office which was: branch@office
2. Click the
Continue
button to configure the Phase 1 Settings.
Define phase 1 settings
1
Set the length of time before Phase 1 is renegotiated in the Key lifetime (m) field.
For this example, leave the Key Lifetime as the default value of 60 minutes.
2. Set the time for when the new key is negotiated before the current key expires in
the Rekeymargin field. For this example, leave the Rekeymargin as the default
value of 10 minutes.
Summary of Contents for SHIVA 1100
Page 38: ...QoS traffic shaping 38 System Administrator s Guide...
Page 44: ...DHCP relay 44 System Administrator s Guide...
Page 66: ...Access control 66 System Administrator s Guide...
Page 122: ...Technical Support 122 System Administrator s Guide...
Page 132: ...132 System Administrator s Guide...