
Configuring VPN
Managing Certificates
Cisco CVR100W Wireless-N VPN Router Administration Guide
111
6
STEP 4
Click
Save
. Then click
Back
to return to the Advanced VPN Setup page.
STEP 5
Click
IPSec Connection Status
to see the status of all site-to-site VPN policies on
the CVR100W.
Managing Certificates
The CVR100W uses digital certificates for IPsec VPN authentication and SSL
validation (for HTTPS). You can generate and sign your own certificates using
functionality available on the CVR100W.
Generating a New Certificate
You can generate a new certificate to replace the existing certificate on the
CVR100W.
To generate a certificate:
STEP 1
Choose
VPN
>
Certificate Management
.
STEP 2
Click the
Generate a New Certificate
radio button.
STEP 3
Click
Generate Certificate
.
Integrity Algorithm
Select the algorithm used to verify the integrity of the
data.
PFS Key Group
Check
Enable
to enable Perfect Forward Secrecy
(PFS) to improve security. While slower, this protocol
helps to prevent intruders by ensuring that a Diffie-
Hellman exchange is performed for every phase-2
negotiation.
Select IKE Policy
Choose the IKE policy that will define the
characteristics of phase 1 of the negotiation. Click
View
to view or edit the existing IKE policy that is
configured on the CVR100W.