UTT Technologies
Chapter 10 VPN
http://www.uttglobal.com
Page
19819819
Encrypt/Auth Algorithms 1 ~ Encrypt/Auth Algorithms 4 (Phase 1):
They refer to
phase 1 proposal that specifies a set of security algorithms for phase 1 negotiation. A
phase 1 proposal includes an encryption algorithm, an authentication algorithm, and
a DH group. You can choose up to four phase 1 proposals.
Encrypt/Auth Algorithms 2 ~ Encrypt/Auth Algorithms 3 (Phase 2):
They refer to
phase 2 proposal that specifies a set of security protocols and algorithms for phase 2
negotiation. You can choose up to four phase 2 proposals together with
P2
Encrypt/Auth Algorithms 1
.
SA Lifetime (Phase 2):
It refers to IPSec SA time lifetime, which specifies the
number of seconds (at least 600 seconds) an IPSec SA will exist before expiring. A
new IPSec SA is negotiated 60 seconds before the existing IPSec SA expires.
Anti-replay:
It is used to enable or disable anti-replay. If you select this check box to
enable anti-replay, the UTT VPN gateway can detect and reject replayed packets (i.e.,
old or duplicate packets) to protect itself against replay attacks.
DPD:
It is used to enable or disable DPD, which allows the UTT VPN gateway to
detect an unresponsive peer. If you select this check box to enable DPD, the UTT
VPN gateway will periodically send DPD heartbeat messages at the specified time
interval (set by the
Heartbeat Interval)
to the remote IPSec device to verify its
availability.
Heartbeat Interval:
It specifies a time interval (in seconds) at which the UTT VPN
gateway will periodically send DPD heartbeat messages to the remote IPSec device
to verify its availability.
PFS:
Perfect Forward Secrecy.
Enable NAT-traversal:
It is used to enable or disable NAT-traversal, which allows
two IPSec devices establish an IPSec tunnel traverse one or more NAT devices.
Port:
It specifies the number of UPD port for NAT traversal. The default value is 4500.
Keepalive Frequency:
It specifies a time interval (in seconds) at which the UTT VPN
gateway will periodically send keepalive packets to the NAT device to keep the NAT
mapping active, so that the NAT mapping doesn’t change until the IKE SA and IPSec
SAs expire. This parameter will only take effect when NAT-traversal is enabled.
Note
IPSec provides two security protocols including AH and ESP for protecting data. AH is
used to provide data authentication service. ESP is used to provide data encryption
service, and/or data authentication service. The UTT VPN gateway supports both AH and
ESP.
In addition, the UTT VPN gateway supports five encryption algorithms including DES,
3DES, AES128, AES192 and AES256, and two authentication algorithms including MD5
and SHA; it also supports Diffie-Hellman exchange including DH groups 1, 2, and 5 for