![Innoband 8860-C1 User Manual Download Page 93](http://html1.mh-extra.com/html/innoband/8860-c1/8860-c1_user-manual_2062335093.webp)
Chapter 4: Configuration
92
Username:
If you are a Dial-Out user (client), enter the username provided by your Host. If you are a Dial-
In user (server), enter your own username.
Password:
If you are a Dial-Out user (client), enter the password provided by the your Host. If you are a
Dial-In user (server), enter your own password.
PPP Authentication Type:
Default is
Auto
if you want the gateway to determine the authentication type to
use. It can also be manually set to CHAP (Challenge Handshake Authentication Protocol) or PAP
(Password Authentication Protocol). The password is sent unencrypted when using PAP. CHAP encrypts
the password before sending and also allows for challenges at different time to ensure that an intruder did
not compromise the client.
Idle Time
: Auto-disconnect the VPN connection when there is no activity on the connection for a
predetermined period of time. 0 means this connection is always on.
Click
Apply
after changing settings.
L2TP over IPSec (L2TP/IPSec) VPN Connection
IPSec:
Enable for enhancing your LT2P VPN security.
Authentication:
Authentication establishes the integrity of the datagram and ensures it is not tampered with
in transmit. There are three options: Message Digest 5 (
MD5
), Secure Hash Algorithm (
SHA1
) or
NONE
.
SHA-1 is more resistant to brute-force attacks but slower than MD5.
MD5:
A one-way hashing algorithm that produces a 128
−
bit hash.
SHA1:
A one-way hashing algorithm that produces a 160
−
bit hash.
Encryption:
Select the encryption method from the pull-down menu. There are four options:
DES
,
3DES
,
AES
and
NONE
. NONE means it is a tunnel only with no encryption. 3DES and AES are more powerful but
increase latency.
DES:
Stands for Data Encryption Standard, it uses 56 bits encryption method.
3DES:
Stands for Triple Data Encryption Standard, it uses 168 (56*3) bits encryption method.
AES:
Stands for Advanced Encryption Standards, it uses 128 bits encryption method.
Perfect Forward Secrecy:
Choose whether to enable PFS using Diffie-Hellman public-key cryptography to
change encryption keys during the second phase of VPN negotiation. This function will provide better
security, but extends the VPN negotiation time. Diffie-Hellman is a public-key cryptography protocol that
allows two parties to establish a shared secret over an unsecured communication channel (i.e. over the
Internet). There are three modes: MODP 768-bit, MODP 1024-bit and MODP 1536-bit. MODP stands for
Modular Exponentiation Groups.
Pre-shared Key:
This is the Internet Key Exchange (IKE) protocol. Both sides should use the same key.
IKE is used to establish a shared security policy and authenticated keys for services (such as IPSec) that
require a key. Before any IPSec traffic can be passed, each gateway must be able to verify the identity of its
peer. This can be done by manually entering the pre-shared key into both sides (gateway or hosts).
Remote Host Name (Optional):
Enter the hostname of the remote VPN device. If the remote hostname
matches, tunnel will be connected; otherwise, it will be dropped.
Cautious:
This is only when the gateway performs as a VPN server. This option should only be used by advanced
users.
Summary of Contents for 8860-C1
Page 1: ...Version 5 51 r1 Last Revised 10 10 2007 ADSL 2 Gateway 8860 C1 User s Manual...
Page 5: ......
Page 13: ......
Page 28: ...Chapter 4 Configuration 27...
Page 83: ...Chapter 4 Configuration 82 Example Configuring a IPSec Host to LAN VPN Connection...
Page 125: ......