Vigor2820 Series User’s Guide
119
mode. The ultimate outcome is to exchange security proposals
to create a protected secure channel.
Main
mode is more
secure than
Aggressive
mode since more exchanges are done
in a secure channel to set up the IPSec session. However, the
Aggressive
mode is faster. The default value in Vigor router is
Main mode.
IKE phase 1 proposal-
To propose the local available
authentication schemes and encryption algorithms to the VPN
peers, and get its feedback to find a match. Two combinations
are available for Aggressive mode and nine for
Main
mode.
We suggest you select the combination that covers the most
schemes.
IKE phase 2 proposal-
To propose the local available
algorithms to the VPN peers, and get its feedback to find a
match. Three combinations are available for both modes. We
suggest you select the combination that covers the most
algorithms.
IKE phase 1 key lifetime-
For security reason, the lifetime of
key should be defined. The default value is 28800 seconds.
You may specify a value in between 900 and 86400 seconds.
IKE phase 2 key lifetime-
For security reason, the lifetime of
key should be defined. The default value is 3600 seconds.
You may specify a value in between 600 and 86400 seconds.
Perfect Forward Secret (PFS)-
The IKE Phase 1 key will be
reused to avoid the computation complexity in phase 2. The
default value is inactive this function.
Local ID -
In
Aggressive
mode, Local ID is on behalf of the IP
address while identity authenticating with remote VPN server.
The length of the ID is limited to 47 characters.
Callback Function
(for i models only)
The callback function provides a callback service as a part of
PPP suite only for the ISDN dial-in user. The router owner
will be charged the connection fee by the telecom.
Require Remote to Callback-
Enable this to let the router to
require the remote peer to callback for the connection
afterwards.
Provide ISDN Number to Remote-
In the case that the
remote peer requires the Vigor router to callback, the local
ISDN number will be provided to the remote peer. Check
here to allow the Vigor router to send the ISDN number to
the remote router. This feature is useful for
i
model only.