Amount of time a VPN tunnel (IPSec SA) is active in this phase. The default value for
Phase 2 is 3600 seconds.
SA Lifetime (Sec)
Select a DH group (
Group 2 or Group 5
) from the drop-down list. DH is a key exchange
protocol, with two groups of different prime key lengths: Group 2 has up to 1,024 bits,
and Group 5 has up to 1,536 bits.
For faster speed and lower security, choose Group 2. For slower speed and higher
security, choose Group 5. Group 2 is selected by default.
Diffie-Hellman (DH) Group
Step 6
For
Manual Keying Mode
, configure the following:
IPsec Configurations
Enter a number (Range 100 - FFFFFFFF, Default 100).
The SPI is an identification tag added to the header while using IPsec for tunneling the
IP traffic. This tag helps the kernel discern between the two traffic streams where
different encryption rules and algorithms may be in use.
Security Parameter Index
(SPI) Incoming
Enter a number (Range 100 - FFFFFFFF, Default 100).
SPI Outgoing
Select an encryption option (
3DES, AES-128, AES-192, or AES-256
) from the
drop-down list. This method determines the algorithm used to encrypt or decrypt
ESP/ISAKMP packets.
Encryption
Enter a number (Hex, 48 characters). Key for decrypting ESP packets received in hex
format.
Key-In
Enter a number (Hex, 48 characters). Key for encrypting the plain packets in hex format.
Key-Out
The authentication method determines how the Encapsulating Security Payload Protocol
(ESP) header packets are validated. The MD5 is a one-way hashing algorithm that
produces a 128-bit digest. The SHA1 is a one-way hashing algorithm that produces a
160-bit digest. The SHA1 is recommended because it is more secure. Make sure that
both ends of the VPN tunnel use the same authentication method. Select an authentication
(
MD5, SHA1 or SHA2-256
).
Authentication
Amount of time an IKE SA is active in this phase. The default value for Phase 1 is
28,800 seconds.
SA Lifetime (Sec)
Enter a number (Hex, 32 characters). Key for decrypting ESP packets received in hex
format.
Key-In
Enter a number (Hex, 32 characters). Key for encrypting the plain packets in hex format.
Key-Out
Step 7
Select an IPsec profile and click
Edit
or
Delete
.
Step 8
To clone an exiting profile, select a profile and click
Clone
.
Step 9
Click
Apply
.
RV345/345P Administration Guide
79
VPN
IPsec Profiles
Содержание RV340 Series
Страница 28: ...RV345 345P Administration Guide 22 Administration Config Management ...
Страница 58: ...RV345 345P Administration Guide 52 QoS Switch Queuing ...
Страница 68: ...RV345 345P Administration Guide 62 LAN Router Advertisement ...
Страница 102: ...RV345 345P Administration Guide 96 VPN VPN Passthrough ...
Страница 108: ...RV345 345P Administration Guide 102 Security IP Source Guard ...
Страница 110: ...RV345 345P Administration Guide 104 Where To Go From Here Where To Go From Here ...