Vigor2952 Series User’s Guide
259
optional and can be used only in IKE aggressive mode.
Local Certificate – Select one of the profiles set in
Certificate Management>>Local Certificate.
IPsec Security Method - This group of fields is a must for
IPsec Tunnels and L2TP with IPsec Policy.
Medium AH (Authentication Header) means data will
be authenticated, but not be encrypted. By default,
this option is active.
High (ESP-Encapsulating Security Payload)- means
payload (data) will be encrypted and authenticated.
Select from below:
DES without Authentication -Use DES encryption
algorithm and not apply any authentication scheme.
DES with Authentication-Use DES encryption algorithm
and apply MD5 or SHA-1 authentication algorithm.
3DES without Authentication-Use triple DES
encryption algorithm and not apply any authentication
scheme.
3DES with Authentication-Use triple DES encryption
algorithm and apply MD5 or SHA-1 authentication
algorithm.
AES without Authentication-Use AES encryption
algorithm and not apply any authentication scheme.
AES with Authentication-Use AES encryption algorithm
and apply MD5 or SHA-1 authentication algorithm.
Advanced - Specify mode, proposal and key life of each IKE
phase, Gateway, etc.
The window of advance setup is shown as below:
IKE phase 1 mode -Select from Main mode and Aggressive
mode. The ultimate outcome is to exchange security
proposals to create a protected secure channel. Main mode
is more secure than Aggressive mode since more exchanges
are done in a secure channel to set up the IPsec session.
However, the Aggressive mode is faster. The default value in
Vigor router is Main mode.
IKE phase 1 proposal-To propose the local available
authentication schemes and encryption algorithms to
the VPN peers, and get its feedback to find a match.
Two combinations are available for Aggressive mode
and nine for Main mode. We suggest you select the
combination that covers the most schemes.
IKE phase 2 proposal-To propose the local available
algorithms to the VPN peers, and get its feedback to
find a match. Three combinations are available for both
modes. We suggest you select the combination that
covers the most algorithms.
IKE phase 1 key lifetime-For security reason, the
lifetime of key should be defined. The default value is
Содержание Vigor 2952 series
Страница 1: ......
Страница 58: ...Vigor2952 Series User s Guide 46 ...
Страница 94: ...Vigor2952 Series User s Guide 82 Below shows an example for successful IPv6 connection based on 6rd mode ...
Страница 106: ...Vigor2952 Series User s Guide 94 ...
Страница 144: ...Vigor2952 Series User s Guide 132 Refresh Reload the record ...
Страница 149: ...Vigor2952 Series User s Guide 137 ...
Страница 244: ...Vigor2952 Series User s Guide 232 This page is left blank ...
Страница 249: ...Vigor2952 Series User s Guide 237 When you choose IPsec you will see the following graphic ...
Страница 314: ...Vigor2952 Series User s Guide 302 This page is left blank ...
Страница 337: ...Vigor2952 Series User s Guide 325 ...
Страница 372: ...Vigor2952 Series User s Guide 360 This page is left blank ...
Страница 385: ...Vigor2952 Series User s Guide 373 ...
Страница 460: ...Vigor2952 Series User s Guide 448 ...
Страница 560: ...Vigor2952 Series User s Guide 548 This page is left blank ...
Страница 588: ...Vigor2952 Series User s Guide 576 ...
Страница 595: ...Vigor2952 Series User s Guide 583 ...
Страница 599: ...Vigor2952 Series User s Guide 587 ...
Страница 601: ...Vigor2952 Series User s Guide 589 P Pa ar rt t I IX X D Dr ra ay yT Te ek k T To oo ol ls s ...
Страница 606: ...Vigor2952 Series User s Guide 594 This page is left blank ...
Страница 607: ...Vigor2952 Series User s Guide 595 P Pa ar rt t X X T Te el ln ne et t C Co om mm ma an nd ds s ...
Страница 635: ...Vigor2952 Series User s Guide 623 ...
Страница 693: ...Vigor2952 Series User s Guide 681 Executation category bas bat com exe inf pif reg scr ...
Страница 802: ...Vigor2952 Series User s Guide 790 This page is left blank ...