Vigor2850 Series User’s Guide
216
scheme.
z
3DES with Authentication-
Use triple DES
encryption algorithm and apply MD5 or SHA-1
authentication algorithm.
z
AES without Authentication
-Use AES encryption
algorithm and not apply any authentication scheme.
z
AES with Authentication-
Use AES encryption
algorithm and apply MD5 or SHA-1 authentication
algorithm.
Advanced -
Specify mode, proposal and key life of each
IKE phase, Gateway, etc.
The window of advance setup is shown as below:
IKE phase 1 mode -
Select from
Main
mode and
Aggressive
mode. The ultimate outcome is to exchange
security proposals to create a protected secure channel.
Main
mode is more secure than
Aggressive
mode since
more exchanges are done in a secure channel to set up the
IPSec session. However, the
Aggressive
mode is faster. The
default value in Vigor router is Main mode.
z
IKE phase 1 proposal-
To propose the local available
authentication schemes and encryption algorithms to
the VPN peers, and get its feedback to find a match.
Two combinations are available for Aggressive mode
and nine for
Main
mode. We suggest you select the
combination that covers the most schemes.
z
IKE phase 2 proposal-
To propose the local available
algorithms to the VPN peers, and get its feedback to
find a match. Three combinations are available for
both modes. We suggest you select the combination
that covers the most algorithms.
z
IKE phase 1 key lifetime-
For security reason, the
lifetime of key should be defined. The default value is
28800 seconds. You may specify a value in between
900 and 86400 seconds.
z
IKE phase 2 key lifetime-
For security reason, the
lifetime of key should be defined. The default value is
3600 seconds. You may specify a value in between
600 and 86400 seconds.
z
Perfect Forward Secret (PFS)-
The IKE Phase 1 key
will be reused to avoid the computation complexity in
phase 2. The default value is inactive this function.
Local ID-
In
Aggressive
mode, Local ID is on behalf
of the IP address while identity authenticating with
remote VPN server. The length of the ID is limited to
Содержание Vigor2850 Series
Страница 1: ......
Страница 2: ...Vigor2850 Series User s Guide ii...
Страница 6: ...Vigor2850 Series User s Guide vi...
Страница 26: ...Vigor2850 Series User s Guide 16 This page is left blank...
Страница 169: ...Vigor2850 Series User s Guide 159 The items categorized under P2P The items categorized under Misc...
Страница 252: ...Vigor2850 Series User s Guide 242...
Страница 311: ...Vigor2850 Series User s Guide 301...
Страница 318: ...Vigor2850 Series User s Guide 308 Below shows the successful activation of Web Content Filter...
Страница 380: ...Vigor2850 Series User s Guide 370 This page is left blank...