. . . . .
V I R T U A L P R I V A T E N E T W O R K S
Virtual Private Networks
Version 3R2
Security Appliance User Guide
7-5
or MD5 provides authentication. Use the following encryption algorithms
to encrypt:
•
Data Encryption Standard (DES)
—Uses either a 40- or 56-bit
encryption algorithm.
•
Triple DES (3DES)
—Uses a more powerful version of DES
encryption. Encrypts the date in three rounds with a 168-bit key.
•
Advanced Encryption Standard (AES)
—An emerging encryption
standard that can use a 128-, 192-, or 256-bit encryption key. This
new standard supports ease of interoperability with other security
appliances as it becomes widely adapted.
THE DIFFIE-HELLMAN GROUP
Users can create a shared secret value using the Diffie-Hellman (DH)
group. This value is secure so that the original message can be sent over
an insecure medium without sending the secret message along with it.
There are a total of three DH groups available for configuration within
the VPN policy:
• DH Group 1—768 bit
• DH Group 2—1024 bit
• DH Group 5—1536 bit
It is more secure to use DH group 5, but as you increase the bit modulus
it will take longer for the key generation process. Because such a variant
exists in the size of the bit modulus, both participants must agree to use
the same DH group.
SECURITY ASSOCIATION
Security Association (SA) is a unidirectional agreement between VPN
appliances that defines the parameters used to secure the data
communication. To allow bi-directional communication, you must define
two SAs, one for each direction:
• Key management (manual key, IKE)
• SA lifetime
• Protocol mode
• Security algorithms and keys
Содержание freeGuard Blaze 2100
Страница 1: ...freeGuard Blaze 2100 User Guide Version 3R2...
Страница 14: ...I NT R O DU C T I O N About Document Conventions 1 4 Security Appliance User Guide Version 3R2 1...
Страница 24: ...G E T T IN G S T A R T E D Installing the freeGuard Blaze 2100 2 10 Security Appliance User Guide Version 3R2 2...
Страница 82: ...SY ST EM MA N AGEM E N T Using Traceroute 4 22 Security Appliance User Guide Version 3R2 4...
Страница 192: ...P OL IC Y CO NF I G URA T IO N About Schedules 9 28 Security Appliance User Guide Version 3R2 9...
Страница 216: ...P R E DEF I N E D SER V IC ES A 4 Security Appliance User Guide Version 3R2 A...