Billion BiGuard VPN Client
Chapter 4: VPN Configuration
20
z
AES:
Stands for Advanced Encryption Standards, you can use 128, 192 or 256 bits as
encryption method.
~
IKE authentication
:
It is a Message Digest algorithm which coverts any length of a message
into a unique set of bits. It is widely used MD5 (Message Digest) and SHA (Secure Hash Algorithm)
algorithms.
SHA is more resistant to brute-force attacks than MD5, however it is slower.
z
MD5:
A one-way hashing algorithm that produces a 128
−
bit hash.
z
SHA:
A one-way hashing algorithm that produces a 160
−
bit hash.
~
IKE key group
(Diffie-Hellman key length)
:
It is a public-key cryptography protocol that
allows two parties to establish a shared secret over an unsecured communication channel (i.e. over
the Internet). There are three modes, MODP 768-bit, MODP 1024-bit and MODP 1536-bit. MODP
stands for Modular Exponentiation Groups.
For more advanced settings, click on
“
P1 Advanced
“.
Phase 1 Advanced configuration
For Advanced features and parameters, click on “P1 Advanced” button into Phase 1 panel.
Advanced features
~
Config Mode
:
If checked, the VPN Client will activate Config-Mode for this tunnel.
Config-Mode allows to the VPN Client to fetch some VPN Configuration information from
the VPN gateway like DNS/WINS server IP addresses. In case Config-Mode is not
available on the remote gateway, please refer to section “Phase2 Advanced” settings to
manually set DNS/WINS server addresses.