Chapter 19 VPN
VMG1312-B10C User’s Guide
217
•
Inside header
: The inside IP header contains the destination IP address of the final system
behind the VPN gateway. The security protocol appears after the outer IP header and before the
inside IP header.
19.3.3 IKE Phases
There are two phases to every IKE (Internet Key Exchange) negotiation – phase 1 (Authentication)
and phase 2 (Key Exchange). A phase 1 exchange establishes an IKE SA and the second one uses
that SA to negotiate SAs for IPSec.
Figure 124
Two Phases to Set Up the IPSec SA
In phase 1 you must:
• Choose a negotiation mode.
• Authenticate the connection by entering a pre-shared key.
• Choose an encryption algorithm.
• Choose an authentication algorithm.
• Choose a Diffie-Hellman public-key cryptography key group
.
• Set the IKE SA lifetime. This field allows you to determine how long an IKE SA should stay up
before it times out. An IKE SA times out when the IKE SA lifetime period expires. If an IKE SA
times out when an IPSec SA is already established, the IPSec SA stays connected.
In phase 2 you must:
• Choose an encryption algorithm.
• Choose an authentication algorithm
• Choose a Diffie-Hellman public-key cryptography key group
.
• Set the IPSec SA lifetime. This field allows you to determine how long the IPSec SA should stay
up before it times out. The Device automatically renegotiates the IPSec SA if there is traffic when
the IPSec SA lifetime period expires. If an IPSec SA times out, then the IPSec router must
renegotiate the SA the next time someone attempts to send traffic.
Summary of Contents for VMG1312-B10C
Page 4: ...Contents Overview VMG1312 B10C User s Guide 4 Diagnostic 265 Troubleshooting 271 ...
Page 14: ...Table of Contents VMG1312 B10C User s Guide 14 ...
Page 15: ...15 PART I User s Guide ...
Page 16: ...16 ...
Page 22: ...Chapter 1 Introducing the Device VMG1312 B10C User s Guide 22 ...
Page 33: ...33 PART II Technical Reference ...
Page 34: ...34 ...
Page 64: ...Chapter 5 Broadband VMG1312 B10C User s Guide 64 ...
Page 100: ...Chapter 6 Wireless VMG1312 B10C User s Guide 100 ...
Page 124: ...Chapter 7 Home Networking VMG1312 B10C User s Guide 124 ...
Page 166: ...Chapter 10 Network Address Translation NAT VMG1312 B10C User s Guide 166 ...
Page 176: ...Chapter 12 Interface Group VMG1312 B10C User s Guide 176 ...
Page 192: ...Chapter 14 Firewall VMG1312 B10C User s Guide 192 ...
Page 198: ...Chapter 16 Parental Control VMG1312 B10C User s Guide 198 ...
Page 208: ...Chapter 18 Certificates VMG1312 B10C User s Guide 208 ...
Page 211: ...Chapter 19 VPN VMG1312 B10C User s Guide 211 Figure 121 IPSec VPN Add ...
Page 224: ...Chapter 20 Log VMG1312 B10C User s Guide 224 ...
Page 234: ...Chapter 24 IGMP Status VMG1312 B10C User s Guide 234 ...
Page 238: ...Chapter 25 xDSL Statistics VMG1312 B10C User s Guide 238 ...
Page 242: ...Chapter 27 User Account VMG1312 B10C User s Guide 242 ...
Page 248: ...Chapter 30 TR 064 VMG1312 B10C User s Guide 248 ...
Page 252: ...Chapter 31 Time Settings VMG1312 B10C User s Guide 252 ...
Page 264: ...Chapter 35 Configuration VMG1312 B10C User s Guide 264 ...
Page 270: ...Chapter 36 Diagnostic VMG1312 B10C User s Guide 270 ...
Page 288: ...Appendix B Legal Information VMG1312 B10C User s Guide 288 ...