![Dell SonicWALL GX250 Скачать руководство пользователя страница 133](http://html.mh-extra.com/html/dell/sonicwall-gx250/sonicwall-gx250_manual_81762133.webp)
SonicWALL Internet Security Appliance Guide Page 133
3. Enter a descriptive name for the
Security Association
, such as "Chicago Office"
or "Remote Management", in the
Name
field.
4. Enter the IP address of the remote VPN gateway, such as another SonicWALL VPN
gateway, in the
IPSec Gateway Address
field. This must be a valid IP address
and is the remote VPN gateway NAT Public Address if NAT is enabled. Enter
"0.0.0.0" if the remote VPN gateway has a dynamic IP address.
5. Define an
SPI
(Security Parameter Index) that the remote SonicWALL uses to
identify the
Security Association
in the
Incoming SPI
field.
6. Define an
SPI
that the local SonicWALL uses to identify the
Security Association
in the
Outgoing SPI
field.
Note
: SPIs should range from 3 to 8 characters in length and include only hexadecimal
characters. Valid hexadecimal characters are “0” to “9”, and “a” to “f” inclusive (0, 1,
2, 3, 4, 5, 6, 7, 8, 9, a, b, c, d, e, f). If you enter an invalid
SPI
, an error message will
be displayed at the bottom of the browser window. An example of a valid
SPI
is
1234abcd.
Note
: Each Security Association must have unique SPIs; no two Security Associations
can share the same SPIs. However, each Security Association’s
Incoming SPI
may be
the same as the
Outgoing SPI
.
7. Select an encryption algorithm from the
Encryption Method
menu. The Son-
icWALL supports the following encryption algorithms:
•
Tunnel Only (ESP NULL)
does not provide encryption or authentication. This op-
tion offers access to computers at private addresses behind NAT and allows unsup-
ported services through the SonicWALL.
•
Encrypt (ESP DES)
uses 56 bit DES to encrypt data. DES is an extremely secure
encryption method, supporting over 72 quadrillion possible encryption keys that
can be used to encrypt data.
•
Fast Encrypt (ESP ARCFour)
uses 56 bit ARCFour to encrypt data. ARCFour is
a secure encryption method and has little impact on the throughput of the Son-
icWALL.
•
Strong Encrypt (ESP 3DES)
uses 168 bit 3DES (Triple DES) to encrypt data.
3DES is considered an almost "unbreakable" encryption method, applying three
DES keys in succession, but it significantly impacts the data throughput of the Son-
icWALL.
•
Strong Encrypt for Check Point (ESP 3DES)
is similar to
Strong Encrypt
(ESP 3DES)
but is interoperable with Check Point Firewall-1.
•
Strong Encrypt and Authenticate (ESP 3DES HMAC MD5)
uses 168 bit 3DES
encryption and HMAC MD5 authentication. 3DES is an extremely secure encryption
method, and HMAC MD5 authentication is used to verify integrity. This method sig-
nificantly impacts the data throughput of the SonicWALL.
integrated_manual.book Page 133 Wednesday, June 13, 2001 6:21 PM