![Draytek Vigor2132 Series Скачать руководство пользователя страница 312](http://html1.mh-extra.com/html/draytek/vigor2132-series/vigor2132-series_user-manual_2529327312.webp)
Vigor2132 Series User’s Guide
304
4
4
.
.
1
1
2
2
.
.
3
3
I
I
P
P
S
S
e
e
c
c
G
G
e
e
n
n
e
e
r
r
a
a
l
l
S
S
e
e
t
t
u
u
p
p
In
IPSec General Setup,
there are two major parts of configuration.
There are two phases of IPSec.
Phase 1: negotiation of IKE parameters including encryption, hash, Diffie-Hellman
parameter values, and lifetime to protect the following IKE exchange, authentication of
both peers using either a Pre-Shared Key or Digital Signature (x.509). The peer that
starts the negotiation proposes all its policies to the remote peer and then remote peer
tries to find a highest-priority match with its policies. Eventually to set up a secure tunnel
for IKE Phase 2.
Phase 2: negotiation IPSec security methods including Authentication Header (AH) or
Encapsulating Security Payload (ESP) for the following IKE exchange and mutual
examination of the secure tunnel establishment.
There are two encapsulation methods used in IPSec,
Transport
and
Tunnel
. The
Transport
mode will add the AH/ESP payload and use original IP header to encapsulate the data payload
only. It can just apply to local packet, e.g., L2TP over IPSec. The
Tunnel
mode will not only
add the AH/ESP payload but also use a new IP header (Tunneled IP header) to encapsulate the
whole original IP packet.
Authentication Header (AH) provides data authentication and integrity for IP packets passed
between VPN peers. This is achieved by a keyed one-way hash function to the packet to create
a message digest. This digest will be put in the AH and transmitted along with packets. On the
receiving side, the peer will perform the same one-way hash on the packet and compare the
value with the one in the AH it receives.
Encapsulating Security Payload (ESP) is a security protocol that provides data confidentiality
and protection with optional authentication and replay detection service.
Available settings are explained as follows:
Item Description
IKE Authentication
Method
This usually applies to those are remote dial-in user or node
(LAN-to-LAN) which uses dynamic IP address and
IPSec-related VPN connections such as L2TP over IPSec
and IPSec tunnel. There is one method offered by Vigor
router for you to authenticate the incoming data coming
from remote dial-in user,
Pre-Shared Key
.
Содержание Vigor2132 Series
Страница 1: ......
Страница 34: ...Vigor2132 Series User s Guide 26 This page is left blank...
Страница 66: ...Vigor2132 Series User s Guide 58 This page is left blank...
Страница 137: ...Vigor2132 Series User s Guide 129 From the Syslog we can find out google is blocked...
Страница 205: ...Vigor2132 Series User s Guide 197...
Страница 232: ...Vigor2132 Series User s Guide 224 After finishing all the settings here please click OK to save the configuration...
Страница 267: ...Vigor2132 Series User s Guide 259 The items categorized under P2P...
Страница 268: ...Vigor2132 Series User s Guide 260 The items categorized under Others...
Страница 349: ...Vigor2132 Series User s Guide 341 After finishing all the settings here please click OK to save the configuration...
Страница 424: ...Vigor2132 Series User s Guide 416 This page is left blank...