SETUP
DOC_DEV_Router setup guide_A
page 31
« Remote WAN IP address » & « Remote WAN Netm
ask” parameters (initiator only):
Enter the WAN IP address of the remote router
Remark :
This address is the address of the router towards which the VPN must be set.
IKE phase 1 section
IKE phase 1 performs mutual authentication between the two parties with the end result of having shared
secret keys.
« Exchange Mode» parameter :
Select Main or Aggressive.
The « Aggressive » mode is simpler and faster than the « Main » mode.
«Encryption algorithm» parameter :
Recommended value : Auto
«Authentication algorithm» parameter :
The « Auto » choice is advised.
SHA1 provides a better security than MD5.
«DH group» parameter (only if the advanced parameters option has been selected) :
Recommended value : group 2.
The same value must be selected for the two routers.
«Life-time» parameter (only if the advanced parameters option has been selected) :
Enter the life-time of the IKE security association.
After that period of time, the IKE step 1 is carried-out again.
IKE phase 2 Section
The purpose of IKE phase two is to negotiate the IPSec parameters (general parameters, encryption, SA life-
time…).
The result of the IKE phase 2 is the encrypted tunnel between the two routers.
«Protocol » parameter :
This parameter enables to set-up the IPSec transport protocol.
AH insures authentication only but does not encrypt the transported data.
ESP ensures routers authentication and data encryption.
ESP will be preferred.
«Data encryption algorithm » parameter :
Recommended value : AES
«Authentication algorithm» parameter :
SHA1 provides a better security than MD5.
«PFS» checkbox :
With PFS disabled, initial keying material is created during the key exchange in phase-1 of the IKE
negotiation. In phase-2 of the IKE negotiation, encryption and authentication session keys will be extracted
from this initial keying material. By using PFS, Perfect Forwarding Secrecy, completely new keying material
will always be created upon re-key. Should one key be compromised, no other key can be derived using that
information.
Summary of Contents for RAS Series
Page 1: ...DOC_DEV_Router setup guide_A RAS IPL SIG _________________ SETUP GUIDE _________________ ...
Page 8: ......
Page 14: ......