IPSec VPNs
Using IPSec Virtual Private Networking (VPN), you can join two or more widely separated private networks
together through the Internet. For example, a company that has two offices in different cities, each with its
own private network, can use VPN to create a secure tunnel between the offices. In addition, remote or
travelling workers can use a VPN client to create a secure tunnel between their computer and an office
private network.
The DFL-500 is an excellent choice for connecting a satellite office or a telecommuter to a main office VPN.
Usually the main office would be protected by a high-capacity product such as the DFL-500-300. The small
office requires the same security and functionality but the smaller user base makes the DFL-500 the product
of choice for protecting smaller networks.
The secure IPSec VPN tunnel makes it appear to all VPN users that they are on physically connected
networks. The VPN protects data passing through the tunnel by encrypting it to guarantee confidentiality. In
addition, authentication guarantees that the data originated from the claimed sender and was not damaged or
altered in transit.
IPSec is an internet security standard for VPN and is supported by most VPN products. DFL-500 IPSec VPNs
can be configured to use Autokey Internet Key Exchange (IKE) or manual key exchange. Autokey key
exchange is easier to configure and maintain than manual key exchange. However, manual key exchange is
available for compatibility with third party VPN products that require it.
IPSec VPN is not supported in Transparent mode.
This chapter describes:
·
Compatibility with third-party VPN products
·
Autokey IPSec VPN between two networks
·
Autokey IPSec VPN for remote clients
·
·
·
Manual key IPSec VPN between two networks
·
Manual key IPSec VPN for remote clients
·
·
Compatibility with third-party VPN products
Because the DFL-500 supports the IPSec industry standard for VPN, you can configure a VPN between a
DFL-500 and any third party VPN client or gateway/firewall that supports IPSec VPN. To successfully
establish the tunnel, the VPN settings must be the same on the DFL-500 and the third party product.
DFL-500 IPSec VPNs support:
·
IPSec Internet Protocol Security standard
·
Automatic IKE based on Pre-shared Key
·
Manual keys that can be fully customized
·
ESP security in tunnel mode
·
3DES (TripleDES) encryption
·
HMAC MD5 authentication/data integrity or HMAC SHA authentication/data integrity
DFL-500 User Manual
53
Содержание DFL-500
Страница 1: ...DFL 500 V2 27 User Manual D Link Systems Inc DFL 500 User Manual 1 ...
Страница 102: ...DFL 500 User Manual 102 ...
Страница 136: ...DFL 500 User Manual 136 ...
Страница 140: ...Registration Register the D Link DFL 500 Office Firewall online at http www dlink com sales reg DFL 500 User Manual 140 ...