manual key
management is used in small static environments or for troubleshooting purposes. Both sides
must use the
same Key Management method.
Encryption Algorithm: There are two methods of encryption, DES and 3DES. The Encryption
method
determines the length of the key used to encrypt/decrypt ESP packets. DES is 56-bit encryption
and 3DES is
168-bit encryption. 3DES is recommended because it is more secure, and both sides must use the
same
Encryption method.
Encryption Key: This field specifies a key used to encrypt and decrypt IP traffic, and the Encryption
Key is
generated yourself. The hexadecimal value is acceptable in this field. Both sides must use the
same
Encryption Key. If DES is selected, the Encryption Key is 16-bit. If users do not fill up to 16-bit, this
field will be
filled up to 16-bit automatically by 0. If 3DES is selected, the Encryption Key is 48-bit. If users do
not fill up to
48-bit, this field will be filled up to 48-bit automatically by 0.
Authentication Algorithm: There are two methods of authentication, MD5 and SHA. The
Authentication method
determines a method to authenticate the ESP packets. MD5 is a one-way hashing algorithm that
produces a
128-bit digest. SHA is a one-way hashing algorithm that produces a 160-bit digest. SHA is
recommended
because it is more secure, and both sides must use the same Authentication method.
Authentication Key: This field specifies a key used to authenticate IP traffic and the Authentication
Key is
generated yourself. The hexadecimal value is acceptable in this field. Both sides must use the
same
Figure 6-29: Manual Key Management
Figure 6-27: Remote Secure Gateway/FQDN
Figure 6-28: Remote Secure Gateway/Any
Authentication key. If MD5 is selected, the Authentication Key is 32-bit. If users do not fill up to
32-bit, this
field will be filled up to 32-bit automatically by 0. If SHA1 is selected, the Authentication Key is 40-
bit. If users
do not fill up to 40-bit, this field will be filled up to 40-bit automatically by 0.
Inbound & Outbound SPI (Security Parameter Index): SPI is carried in the ESP (Encapsulating
Security Payload
Protocol) header and enables the receiver and sender to select the SA, under which a packet
should be
processed. The hexadecimal values is acceptable, and the valid range is 100~ffffffff. Each tunnel
must have a
unique Inbound SPI and Outbound SPI. No two tunnels share the same SPI. The Incoming SPI
here must match
the Outgoing SPI value at the other end of the tunnel, and vice versa.
• Status. Click the
Advanced VPN Tunnel Setup
key and the Advanced VPN Tunnel Setup
screen will appear.
See Figure 6-30.
When finished making your changes on this tab, click the
Save Settings
button to save these
changes, or click
the
Cancel Changes
button to undo your changes. Advanced VPN Tunnel Setup
From the Advanced VPN Tunnel Setup screen, shown in Figure 6-27, you can adjust the settings