Twin WAN Series – User Guide | v1
ESP Mode
Only tunnel mode is available. This mode offers the most protection against an intruder
who tries to intercept VPN packets.
Figure 18-d. Key Management Console.
Key Management allows you to define various settings for the negotiation and
authentication. This menu must be configured the same on both local and remote
endpoints.
Key Management & Action - Settings
Key Type
There are two key types- manual key and auto key- available for the key exchange
management:
•
Manual Key
- When Manual Key is selected the page refreshes with a
modified interface. Manual Key by the nature of its design works with NAT it
is more complex to set up since it requires for you to set outgoing and
incoming SPI as well as Authentication and encryption Keys. Both the local
and the remote gateways must have the same keys in order to authenticate.
o
Encryption Key
- This field specifies a key to encrypt and decrypt IP
traffic.
o
Authentication Key
- This field specifies a key use to authentication IP
traffic.
o
Inbound/outbound SPI (Security Parameter Index)
is carried on the
ESP header. Each tunnel must have a unique inbound and outbound SPI
and no two tunnels share the same SPI. Notice that Inbound SPI must
match the other router’s outbound SPI.
Copyright © 2005 WINS International, LLC dba XiNCOM | All rights reserved.
66