P-662H/HW-D Series User’s Guide
256
Chapter 16 VPN Screens
Negotiation Mode Select
Main
or
Aggressive
from the drop-down list box. Multiple SAs connecting
through a secure gateway must have the same negotiation mode.
Pre-Shared Key Type your pre-shared key in this field. A pre-shared key identifies a
communicating party during a phase 1 IKE negotiation. It is called "pre-shared"
because you have to share it with another party before you can communicate with
them over a secure connection.
Type from 8 to 31 case-sensitive ASCII characters or from 16 to 62 hexadecimal
("0-9", "A-F") characters. You must precede a hexadecimal key with a "0x” (zero
x), which is not counted as part of the 16 to 62-character range for the key. For
example, in "0x0123456789ABCDEF", “0x” denotes that the key is hexadecimal
and “0123456789ABCDEF” is the key itself.
Both ends of the VPN tunnel must use the same pre-shared key. You will receive
a “PYLD_MALFORMED” (payload malformed) packet if the same pre-shared key
is not used on both ends.
Encryption
Algorithm
Select
DES
,
3DES
or
AES
from the drop-down list box.
When you use one of these encryption algorithms for data communications, both
the sending device and the receiving device must use the same secret key, which
can be used to encrypt and decrypt the message or to generate and verify a
message authentication code. The DES encryption algorithm uses a 56-bit key.
Triple DES (
3DES
) is a variation on
DES
that uses a 168-bit key. As a result,
3DES
is more secure than
DES
. It also requires more processing power, resulting
in increased latency and decreased throughput. This implementation of AES uses
a 128-bit key.
AES
is faster than
3DES
.
Authentication
Algorithm
Select
SHA1
or
MD5
from the drop-down list box.
MD5
(Message Digest 5) and
SHA1
(Secure Hash Algorithm) are hash algorithms used to authenticate packet
data. The
SHA1
algorithm is generally considered stronger than
MD5
, but is
slower. Select
MD5
for minimal security and
SHA-1
for maximum security.
SA Life Time
(Seconds)
Define the length of time before an IKE SA automatically renegotiates in this field.
It may range from 60 to 3,000,000 seconds (almost 35 days).
A short SA Life Time increases security by forcing the two VPN gateways to
update the encryption and authentication keys. However, every time the VPN
tunnel renegotiates, all users accessing remote resources are temporarily
disconnected.
Key Group You must choose a key group for phase 1 IKE setup.
DH1
(default) refers to
Diffie-Hellman Group 1 a 768 bit random number.
DH2
refers to Diffie-Hellman
Group 2 a 1024 bit (1Kb) random number.
Phase 2
Active Protocol Use the drop-down list box to choose from
ESP
or
AH
.
Encryption
Algorithm
This field is available when you select
ESP
in the
Active Protocol
field.
Select
DES
,
3DES
,
AES
or
NULL
from the drop-down list box.
When you use one of these encryption algorithms for data communications, both
the sending device and the receiving device must use the same secret key, which
can be used to encrypt and decrypt the message or to generate and verify a
message authentication code. The DES encryption algorithm uses a 56-bit key.
Triple DES (
3DES
) is a variation on DES that uses a 168-bit key. As a result,
3DES
is more secure than
DES
. It also requires more processing power, resulting
in increased latency and decreased throughput. This implementation of AES uses
a 128-bit key.
AES
is faster than
3DES
.
Select
NULL
to set up a tunnel without encryption. When you select
NULL
, you
do not enter an encryption key.
Table 95
Advanced VPN Policies
LABEL
DESCRIPTION
Summary of Contents for 802.11g ADSL 2+ 4-Port Security Gateway HW-D Series
Page 2: ......
Page 10: ...P 662H HW D Series User s Guide 10 Customer Support ...
Page 24: ...P 662H HW D Series User s Guide 24 Table of Contents ...
Page 32: ...P 662H HW D Series User s Guide 32 List of Figures ...
Page 38: ...P 662H HW D Series User s Guide 38 List of Tables ...
Page 64: ...P 662H HW D Series User s Guide 64 Chapter 2 Introducing the Web Configurator ...
Page 84: ...P 662H HW D Series User s Guide 84 Chapter 4 Bandwidth Management Wizard ...
Page 108: ...P 662H HW D Series User s Guide 108 Chapter 5 WAN Setup ...
Page 122: ...P 662H HW D Series User s Guide 122 Chapter 6 LAN Setup ...
Page 156: ...P 662H HW D Series User s Guide 156 Chapter 8 DMZ ...
Page 202: ...P 662H HW D Series User s Guide 202 Chapter 11 Firewall Configuration ...
Page 210: ...P 662H HW D Series User s Guide 210 Chapter 12 Anti Virus Packet Scan ...
Page 214: ...P 662H HW D Series User s Guide 214 Chapter 13 Content Filtering ...
Page 232: ...P 662H HW D Series User s Guide 232 Chapter 14 Content Access Control ...
Page 238: ...P 662H HW D Series User s Guide 238 Chapter 15 Introduction to IPSec ...
Page 273: ...P 662H HW D Series User s Guide Chapter 17 Certificates 273 Figure 144 My Certificate Details ...
Page 292: ...P 662H HW D Series User s Guide 292 Chapter 18 Static Route ...
Page 304: ...P 662H HW D Series User s Guide 304 Chapter 19 Bandwidth Management ...
Page 308: ...P 662H HW D Series User s Guide 308 Chapter 20 Dynamic DNS Setup ...
Page 332: ...P 662H HW D Series User s Guide 332 Chapter 22 Universal Plug and Play UPnP ...
Page 338: ...P 662H HW D Series User s Guide 338 Chapter 23 System ...
Page 344: ...P 662H HW D Series User s Guide 344 Chapter 24 Logs ...
Page 350: ...P 662H HW D Series User s Guide 350 Chapter 25 Tools ...
Page 364: ...P 662H HW D Series User s Guide 364 Chapter 27 Troubleshooting ...
Page 368: ...P 662H HW D Series User s Guide 368 Product Specifications ...
Page 372: ...P 662H HW D Series User s Guide 372 Appendix C Wall mounting Instructions ...
Page 408: ...P 662H HW D Series User s Guide 408 Appendix F Wireless LANs ...
Page 420: ...P 662H HW D Series User s Guide 420 Appendix H Command Interpreter ...
Page 436: ...P 662H HW D Series User s Guide 436 Appendix L NetBIOS Filter Commands ...
Page 462: ...P 662H HW D Series User s Guide 462 Appendix M Internal SPTGEN ...
Page 484: ...P 662H HW D Series User s Guide 484 Appendix P Triangle Route ...