VPN and Remote Access Setup
8-16
IKE phase 1 mode:
Main mode and Aggressive mode. Most
VPN servers support Main mode and Aggressive mode is a
more recent implementation to speed up the negotiation
process, but may incur less security. The default is Main
mode for consideration of greatest compatibility.
IKE phase 1 proposal:
Then the router will query the
remote VPN server if it supports the designated algorithm.
There are two options of query for Aggressive mode and nine
options for Main mode. We suggest to select the latest one,
“DES_MD5_G1/DES_SHA1_G1/3DES_MD5_G1/3DES_MD
5_G2”, for Main mode.
IKE phase 1 key lifetime
: For the greater security, the router
should limit the key lifetime. The default key lifetime is 28800
seconds. We suggest you specify a value in between 900 and
86400 seconds.
IKE phase 2 key lifetime
: For the greater security, the router
should limit the key lifetime. The default key lifetime is 3600
seconds. We suggest you specify a value in between 600 and
86400 seconds.
Perfect Forward Secret
: If this function enabled, the function
the Phase 1 key will be reused to reduce the computation
complexity in phase 2. Otherwise, a new key will be generated
for phase 2 key. The default of this option is inactive.
Local ID
: This function is used in Aggressive mode. It
is on behalf of the IP address to perform identity
Содержание Vigor 2200V
Страница 1: ......
Страница 5: ...iv Preamble of DrayTek Vigor2200V series All Rights Reserved Hardware Connection ...
Страница 49: ...NAT Setup 5 9 ...
Страница 75: ...Firewall Setup 6 26 ...
Страница 108: ...VPN and Remote Access Setup 8 21 2 Create a LAN to LAN profile at Head Office ...
Страница 109: ...VPN and Remote Access Setup 8 22 3 Create a LAN to LAN profile at Branch Office ...