36
dangers such as password and bank account information stolen and tampered, user identity
imitated, suffering from malicious network attack, etc. After disposal of IPSec on the network,
it can protect data transmission and reduce risk of information disclosure.
IPSec is a group of open network security protocol made by IETF, which can ensure the security of
data transmission between two parties on the Internet via data origin authentication, data
encryption, data integrity and anti-replay function on the IP level. It is able to reduce the risk of
disclosure and guarantee data integrity and confidentiality and well as maintain security of
service transmission of users.
IPSec, including AH, ESP and IKE, can protect one and more date flows between hosts, between
host and gateway, and between gateways. The security protocols of AH and ESP can ensure
security and IKE is used for cipher code exchange.
IPSec can establish bidirectional Security Alliance on the IPSec peer pairs to form a secure and
interworking IPSec tunnel and to realize the secure transmission of data on the Internet.
From navigation tree, select VPN>>IPSec Settings, then enter “IPSec Settings” page.
Table 3-6-1 Parameters of IPSec Settings
IPSec settings
Function description: 1. Select whether to enable NATT, generally this is enabled, unless it is
confirmed that there is no NAT router in the network. In order to keep VPN
tunnel connected, NATT interval should be properly set.
2. Select whether to enable compression and debug mode.
Parameters
Description
Default
Enable NAT-Traversal (NATT)
Click to enable NAT-Traversal
Enable
Keep alive time interval of
NAT
Set alive time interval of NAT
60 s
Enable Compression
Click to enable compression
Enable
Force NATT
Click to enable force NATT
Disable
Dynamic NATT Port
Click to enable dynamic NATT port
Disable
3.6.2 IPSec Tunnels
From navigation tree, select VPN>>IPSec Tunnels, enter "IPSec Tunnels" and click <add>.
Table 3-6-2 Parameters of IPSec Tunnels
IPSec Tunnels
Function description: Configure IPSec tunnels