Doc. Version 1.0
98
H8922 3G/4G Router User Manual
Parameter
Details
Operation
Hash
The second stage of hash algorithm
selection
Select from Dropdown List
⚫
md5
⚫
sha1
⚫
Sha2_256
Group Name
Used when perfect forward encryp-
tion is enabled, here configured as the
key length for IPSec second-phase SA
negotiation.
Select from Dropdown List
⚫
group768
⚫
group1024
⚫
group1536
⚫
group2048
⚫
group3072
⚫
Grouo4096
PFS
Enabling or disabling perfect forward
encryption, enabling perfect forward
encryption increases system over-
head, but increases IPSec security.
Select from Dropdown List
Select open or close according to the set-
tings of the peer IPSec server.
Lifetime
IPSec SA key life time
Value area: 120~86400
Unit: second
Local Protoport
Configure the protocol and port that
the local end needs to encrypt.
Manual input, the front box enters the
protocol code, and the rear box enters
the port.
Remote Proto-
port
Configure the protocol and port that
the peer needs to encrypt.
Manual input, the front box enters the
protocol code, and the rear box enters
the port.
Transport Mode
Supports tunnel, transport and auto.
Select from Dropdown List
⚫
auto
⚫
Transport
⚫
tunnel
Local Subnet
Set local subnet
No need to set for “transport” mode,
only for “auto” and “tunnel”. Format:
A.B.C.D/M
Remote Subnet
To set local subnet
No
need to set for “transport” mode,
only for “auto” and “tunnel”. Format:
A.B.C.D/M
Single click “save” to finish the configuration of phase 2 .
Among the above parameters, the transmission protocol, encryption method, hash algorithm, DH group, per-
fect forward encryption, key lifetime, etc. must be consistent with the IPSec server configuration; if the trans-
mission mode is set to automatic or tunnel mode, the local subnet and the remote terminal network must be
consistent with the configuration of the remote subnet and local subnet in the IPSec server.
Summary of Contents for H8922
Page 1: ...User Manual H8922 3G 4G Router www hongdian com...
Page 157: ......