Prestige 653HWI Series User’s Guide
17-2
VPN
Screens
Table 17-1 AH and ESP
ESP AH
Select
DES
for minimal security and
3DES
for maximum.
Select
NULL
to set up a tunnel without encryption.
Select
MD5
for minimal security and
SHA-1
for
maximum security.
DES
(default)
Data Encryption Standard (DES) is a widely used method
of data encryption using a private (secret) key. DES
applies a 56-bit key to each 64-bit block of data.
MD5
(default)
MD5 (Message Digest 5) produces a 128-bit
digest to authenticate packet data.
3DES
Triple DES (3DES) is a variant of DES, which iterates
three times with three separate keys (3 x 56 = 168 bits),
effectively doubling the strength of DES.
SHA1
SHA1 (Secure Hash Algorithm) produces a
160-bit digest to authenticate packet data.
Select
DES
for minimal security and
3DES
for maximum.
Select
NULL
to set up a tunnel without encryption.
Select
MD5
for minimal security and
SHA-1
for
maximum security.
17.3 My IP Address
My IP Address
is the WAN IP address of the Prestige. If this field is configured as 0.0.0.0, then the Prestige
will use the current Prestige WAN IP address (static or dynamic) to set up the VPN tunnel. The Prestige has
to rebuild the VPN tunnel if the
My IP Address
changes after setup.
17.4 Secure Gateway Address
Secure Gateway Address
is the WAN IP address or domain name of the remote IPSec router (secure
gateway).
If the remote secure gateway has a static WAN IP address, enter it in the
Secure Gateway Address
field.
You may alternatively enter the remote secure gateway’s domain name (if it has one) in the
Secure Gateway
Address
field.
You can also enter a remote secure gateway’s domain name in the
Secure Gateway Address
field if the
remote secure gateway has a dynamic WAN IP address and is using DDNS. The Prestige has to rebuild the
VPN tunnel each time the remote secure gateway’s WAN IP address changes (there may be a delay until the
DDNS servers are updated with the remote gateway’s new WAN IP address).
17.4.1 Dynamic Secure Gateway Address
If the remote secure gateway has a dynamic WAN IP address and does not use DDNS, enter 0.0.0.0 as the
secure gateway’s address. In this case only the remote secure gateway can initiate SAs. This may be useful
Summary of Contents for Prestige 653HWI series
Page 30: ......
Page 62: ......
Page 64: ......
Page 88: ......
Page 108: ...Prestige 653HWI Series User s Guide 7 20 WAN Setup Figure 7 10 Traffic Redirect LAN Setup...
Page 112: ......
Page 114: ......
Page 134: ......
Page 136: ......
Page 156: ......
Page 172: ......
Page 184: ......
Page 186: ......
Page 192: ......
Page 200: ...Prestige 653HWI Series User s Guide 17 8 VPN Screens Figure 17 3 VPN IKE...
Page 222: ......
Page 242: ......
Page 262: ......
Page 263: ...Maintenance VIII Part VIII Maintenance This part covers the maintenance screens...
Page 264: ......
Page 266: ...Prestige 653HWI Series User s Guide 22 2 Maintenance Figure 22 1 System Status...
Page 282: ......
Page 292: ......
Page 312: ......
Page 338: ......
Page 368: ......
Page 408: ......
Page 430: ......
Page 434: ......
Page 444: ......
Page 450: ......
Page 466: ......
Page 474: ......
Page 480: ......
Page 492: ......
Page 497: ...Prestige 653HWI Series User s Guide PPPoE E 3 Diagram E 2 Prestige as a PPPoE Client...
Page 498: ......
Page 500: ......
Page 540: ......
Page 554: ......