68
VPN configuration
NN47928-500
NN47928-500
DH Group
Select the required Diffie-Hellman (DH) group. DH key exchange is used
to establish preshared keys.
Select Group 1 – IKE uses a 768-bit Diffie- Hellman Prime modules group
for performing the new Diffie-Hellman exchange.
Select Group 2 – IKE uses a 1024-bit Diffie- Hellman Prime modules
group for performing the new Diffie-Hellman exchange.
Select
Group 5 – IKE uses a 1536-bit Diffie- Hellman Prime modules
group for performing the new Diffie-Hellman exchange.
Exchange
Select the exchange mode.
Select Main for the highest level of Security.
Select Aggressive for speed.
Life Time
Select the lifetime unit. It can be seconds, minutes, or hours.
Life Time Value
Type the lifetime value.
Peer Identity Type/Value
Select the identity type to access the remote network. Select one of the
following:
•
IPV4 - IP address
•
FQDN - Fully Qualified Domain Name
•
EMAIL - email address of the user
•
KEYID - uniquely identifies the peer
Select the associated value from the list. The list contains the Remote
Identity values entered on VPN Global Settings.
Local Identity Type/Value
Select the identity type to access the local network. Select one of the
following:
•
IPV4 - IP address
•
FQDN - Fully Qualified Domain Name
•
EMAIL - email address of the user
•
KEYID - uniquely identifies the peer
Type the associated value.
IP Sec Phase 2 Proposal table
Protocol
Select the authentication protocol.
Select
ESP, IPSec encrypts and authenticates.
Select AH, IPSec only authenticates.
Encryption
Select the IPSec Encryption. Select one of the following options:
•
null – indicates no standard is used for IPsec encryption.
•
Data Encryption Standard (DES) – indicates a standard for encrypting
data that uses a 64 bit key to encrypt data, but only 56 bits are usable.
This standard is considered inadequate for data protection as this
standard do not match the speed of computer.
•
Triple Data Encryption Standard (3DES) – processes each block of
data using a different key each time resulting in a significantly more
secure message.
•
Advanced Encryption Standard (AES-128, AES-192, AES-256) – has
a fixed block size of 128 bits and a key size of 128, 192 or 256 bits.
Due to the fixed block size of 128 bits, AES operates on a 4x4 array of
bytes.
Variable
Value
Summary of Contents for BSG12aw 1.0
Page 14: ...14 Introduction NN47928 500 NN47928 500 ...
Page 22: ...22 WAN configuration NN47928 500 NN47928 500 ...
Page 54: ...54 SIP configuration NN47928 500 NN47928 500 ...
Page 80: ...80 QoS configuration NN47928 500 NN47928 500 ...
Page 82: ...82 Advanced configuration NN47928 500 NN47928 500 ...
Page 110: ...110 LAN advanced configuration NN47928 500 NN47928 500 ...
Page 144: ...144 IP routing advanced configuration NN47928 500 NN47928 500 ...
Page 152: ...152 DHCP advanced configuration NN47928 500 NN47928 500 ...
Page 164: ...164 QoS advanced configuration NN47928 500 NN47928 500 ...
Page 176: ...176 VPN advanced configuration NN47928 500 NN47928 500 ...
Page 200: ...200 Port management advanced configuration NN47928 500 NN47928 500 ...