VigorIPPBX 2820 Series User’s Guide
298
and
Password
of the mutual authentication peer.
Start IP Address
Enter a start IP address for the dial-in PPP connection. You
should choose an IP address from the local private network.
For example, if the local private network is
192.168.1.0/255.255.255.0, you could choose
192.168.1.200 as the Start IP Address. But, you have to
notice that the first two IP addresses of 192.168.1.200 and
192.168.1.201 are reserved for ISDN remote dial-in user.
6
6
.
.
7
7
.
.
3
3
I
I
P
P
S
S
e
e
c
c
G
G
e
e
n
n
e
e
r
r
a
a
l
l
S
S
e
e
t
t
u
u
p
p
In
IPSec General Setup,
there are two major parts of configuration.
There are two phases of IPSec.
Phase 1: negotiation of IKE parameters including encryption, hash, Diffie-Hellman
parameter values, and lifetime to protect the following IKE exchange, authentication of
both peers using either a Pre-Shared Key or Digital Signature (x.509). The peer that
starts the negotiation proposes all its policies to the remote peer and then remote peer
tries to find a highest-priority match with its policies. Eventually to set up a secure
tunnel for IKE Phase 2.
Phase 2: negotiation IPSec security methods including Authentication Header (AH) or
Encapsulating Security Payload (ESP) for the following IKE exchange and mutual
examination of the secure tunnel establishment.
There are two encapsulation methods used in IPSec,
Transport
and
Tunnel
. The
Transport
mode will add the AH/ESP payload and use original IP header to encapsulate the data
payload only. It can just apply to local packet, e.g., L2TP over IPSec. The
Tunnel
mode will
not only add the AH/ESP payload but also use a new IP header (Tunneled IP header) to
encapsulate the whole original IP packet.
Authentication Header (AH) provides data authentication and integrity for IP packets passed
between VPN peers. This is achieved by a keyed one-way hash function to the packet to
create a message digest. This digest will be put in the AH and transmitted along with packets.
On the receiving side, the peer will perform the same one-way hash on the packet and
compare the value with the one in the AH it receives.
Encapsulating Security Payload (ESP) is a security protocol that provides data
confidentiality and protection with optional authentication and replay detection service.
IKE Authentication
This usually applies to those are remote dial-in user or node
Содержание Vigor IPPBX 2820n
Страница 1: ......
Страница 2: ......
Страница 3: ...VigorIPPBX 2820 Series User s Guide Version 2 7 Based on Firmware Version V3 5 9 Date 10 12 2013...
Страница 25: ...VigorIPPBX 2820 Series User s Guide 17 Online status for Static IP for WAN1 Online status for DHCP WAN1...
Страница 28: ...VigorIPPBX 2820 Series User s Guide 20 This page is left blank...
Страница 196: ...VigorIPPBX 2820 Series User s Guide 188 This page is left blank...
Страница 245: ...VigorIPPBX 2820 Series User s Guide 237...
Страница 246: ...VigorIPPBX 2820 Series User s Guide 238...
Страница 362: ...VigorIPPBX 2820 Series User s Guide 354 Refresh Click it to reload the page...
Страница 370: ...VigorIPPBX 2820 Series User s Guide 362 This page is left blank...
Страница 375: ...VigorIPPBX 2820 Series User s Guide 367...