ER75s
Continued from previous page
Item
Description
Authenticate Mode
By this parameter can be set authentication:
•
Pre-shared key
– shared key for both off-side tunnel
•
X.509 Certificate
– allows X.509 certification in multiclient
mode
Pre-shared Key
Sharable key for both parties tunnel.
CA Certificate
This certificate is necessary to insert Authentication mode x.509.
Remote Certificate
This certificate is necessary to insert Authentication mode x.509.
Local Certificate
This certificate is necessary to insert Authentication mode x.509.
Local Private Key
This private key is necessary to insert Authentication mode
x.509.
Local Passphrase
This Local Passphrase is necessary to insert Authentication
mode x.509.
Extra Options
Use this parameter to define additional parameters of the IPsec
tunnel, for example secure parameters etc.
Table 41: OpenVPN tunnels configuration
The certificates and private keys have to be in PEM format. As certificate it is possible to
use only certificate which has start and stop tag certificate.
Random time, after which it will re-exchange of new keys are defined:
Lifetime - (Rekey random value in range (from 0 to Rekey margin * Rekey Fuzz/100))
By default, the repeated exchange of keys held in the time range:
•
Minimal time: 1h - (9m + 9m) = 42m
•
Maximal time: 1h - (9m + 0m) = 51m
When setting the times for key exchange is recommended to leave the default setting in
which tunnel has guaranteed security. When set higher time, tunnel has smaller operating
costs and smaller the safety. Conversely, reducing the time, tunnel has higher operating costs
and higher safety of the tunnel.
The changes in settings will apply after pressing the
Apply
button.
64
Содержание ER75s
Страница 1: ...EDGE router ER75s USER MANUAL ...
Страница 40: ...ER75s Figure 24 Topology of example LAN configuration 1 32 ...
Страница 42: ...ER75s Figure 26 Topology of example LAN configuration 2 Figure 27 Example LAN configuration 2 34 ...
Страница 51: ...ER75s Continued from previous page Item Description Table 28 Configuration of switching between APNs I 43 ...
Страница 54: ...ER75s Figure 33 Mobile WAN configuration 46 ...
Страница 59: ...ER75s Figure 38 Firewall configuration 51 ...
Страница 76: ...ER75s Figure 49 IPsec tunnels configuration 68 ...
Страница 78: ...ER75s Figure 53 Topology of GRE tunnel configuration 70 ...