
Chapter 14 VPN
P-2612HW Series User’s Guide
269
Remote Start
Port
0 is the default and signifies any port. Type a port number from 0 to
65535. Some of the most common IP ports are: 21, FTP; 53, DNS; 23,
Telnet; 80, HTTP; 25, SMTP; 110, POP3.
End
Enter a port number in this field to define a port range. This port
number must be greater than that specified in the previous field. If
Remote Start Port is left at 0, End will also remain at 0.
Phase 1
Negotiation
Mode
Select Main or Aggressive from the drop-down list box. Multiple SAs
connecting through a secure gateway must have the same negotiation
mode.
Pre-Shared Key
Type your pre-shared key in this field. A pre-shared key identifies a
communicating party during a phase 1 IKE negotiation. It is called
"pre-shared" because you have to share it with another party before
you can communicate with them over a secure connection.
Type from 8 to 31 case-sensitive ASCII characters or from 16 to 62
hexadecimal ("0-9", "A-F") characters. You must precede a
hexadecimal key with a "0x” (zero x), which is not counted as part of
the 16 to 62-character range for the key. For example, in
"0x0123456789ABCDEF", “0x” denotes that the key is hexadecimal
and “0123456789ABCDEF” is the key itself.
Both ends of the VPN tunnel must use the same pre-shared key. You
will receive a “PYLD_MALFORMED” (payload malformed) packet if the
same pre-shared key is not used on both ends.
Encryption
Algorithm
Select DES, 3DES or AES from the drop-down list box.
When you use one of these encryption algorithms for data
communications, both the sending device and the receiving device
must use the same secret key, which can be used to encrypt and
decrypt the message or to generate and verify a message
authentication code. The DES encryption algorithm uses a 56-bit key.
Triple DES (3DES) is a variation on DES that uses a 168-bit key. As a
result, 3DES is more secure than DES. It also requires more
processing power, resulting in increased latency and decreased
throughput. This implementation of AES uses a 128-bit key. AES is
faster than 3DES.
Authentication
Algorithm
Select SHA1 or MD5 from the drop-down list box. MD5 (Message
Digest 5) and SHA1 (Secure Hash Algorithm) are hash algorithms
used to authenticate packet data. The SHA1 algorithm is generally
considered stronger than MD5, but is slower. Select MD5 for minimal
security and SHA-1 for maximum security.
SA Life Time
(Seconds)
Define the length of time before an IPSec SA automatically
renegotiates in this field. It may range from 60 to 3,000,000 seconds
(almost 35 days).
A short SA Life Time increases security by forcing the two VPN
gateways to update the encryption and authentication keys. However,
every time the VPN tunnel renegotiates, all users accessing remote
resources are temporarily disconnected.
Key Group
You must choose a key group for phase 1 IKE setup. DH1 (default)
refers to Diffie-Hellman Group 1 a 768 bit random number. DH2 refers
to Diffie-Hellman Group 2 a 1024 bit (1Kb) random number.
Table 83
Security > VPN > Setup > Edit > Advanced Setup (continued)
LABEL
DESCRIPTION
Summary of Contents for P-2612HW-F1 -
Page 2: ......
Page 8: ...Safety Warnings P 2612HW Series User s Guide 8...
Page 10: ...Contents Overview P 2612HW Series User s Guide 10...
Page 22: ...Table of Contents P 2612HW Series User s Guide 22...
Page 24: ...24...
Page 56: ...Chapter 3 Wizards P 2612HW Series User s Guide 56...
Page 88: ...88...
Page 120: ...Chapter 6 WAN Setup P 2612HW Series User s Guide 120...
Page 136: ...Chapter 7 LAN Setup P 2612HW Series User s Guide 136...
Page 168: ...Chapter 8 Wireless LAN P 2612HW Series User s Guide 168...
Page 184: ...Chapter 9 Network Address Translation NAT P 2612HW Series User s Guide 184...
Page 250: ...Chapter 12 Firewall P 2612HW Series User s Guide 250...
Page 290: ...Chapter 14 VPN P 2612HW Series User s Guide 290...
Page 320: ...Chapter 15 Certificates P 2612HW Series User s Guide 320...
Page 324: ...Chapter 16 Static Route P 2612HW Series User s Guide 324...
Page 356: ...Chapter 19 Dynamic DNS Setup P 2612HW Series User s Guide 356...
Page 382: ...Chapter 21 Universal Plug and Play UPnP P 2612HW Series User s Guide 382...
Page 384: ...384...
Page 406: ...Chapter 23 Logs P 2612HW Series User s Guide 406...
Page 458: ...458...
Page 494: ...Appendix B Pop up Windows JavaScripts and Java Permissions P 2612HW Series User s Guide 494...
Page 530: ...Appendix D Wireless LANs P 2612HW Series User s Guide 530...