73 / 92
Advanced Options)
authenticity of data packet from
hacker intercepting data packet or
inserting false data packet on the
internet.
ESP:
encrypt the user data
needing protection, and then
enclose into IP packet for the
purpose of confidentiality of data.
IPSec Mode (Enable
Advanced Options)
Tunnel Mode:
besides source
host and destination host, special
gateway will be operated with
password to ensure the safety
from gateway to gateway.
Transmission Mode
: source host
and destination host must directly
execute all passwords operations
for the purpose of higher work
efficiency, but comparing with
tunnel mode the security will be
inferior.
Tunnel Mode
Tunnel Type
Host-Host, Host-Subnet, Subnet-
Host, Subnet-Subnet
Subnet-Subnet
Local Subnet
Set local subnet
192.168.2.1
Local Netmask
Set local netmask
255.255.255.0
Remote Subnet
Set remote subnet
0.0.0.0
Remote Netmask
Set remote netmask
255.255.255.0
Phase 1 Parameters
IKE Policy
Select IKE policy
3DES-MD5-
DH2
IKE Lifetime
Set IKE lifetime
86400
seconds
Local ID Type
FQDN/ User FQDN/IP
IP address
Remote ID Type
FQDN/User FQDN/ IP
IP address
Authentication Type
Shared Key or Certificate
Shared Key
Key (only for Shared Key)
Set IPSec VPN key
N/A
Phase 2Parameters
IPSec Policy
Select IKE policy
3DES-MD5-
96
IPSec Lifetime
Set IKE lifetime
3600 seconds
Perfect Forward Secrecy
(PFS)
The exposure of one key will not
affect the data security protected
by other keys.
Disable
Link Detection Parameters
DPD Interval
Used for detection interval of
IPSec neighbor state.
After initiating DPD, If receiving
60 seconds