Chapter 4: Configuration
77
DES:
Stands for Data Encryption Standard, it uses 56 bits encryption method.
3DES:
Stands for Triple Data Encryption Standard, it uses 168 (56*3) bits encryption method.
AES:
Stands for Advanced Encryption Standards, you can use 128, 192 or 256 bits encryption
method.
Diffie-Hellman Group:
It is a public-key cryptography protocol that allows two parties to establish a shared
secret over an unsecured communication channel. There are three modes: MODP 768-bit, MODP 1024-bit
and MODP 1536-bit. MODP stands for Modular Exponentiation Groups.
Local ID:
Type:
Specify local ID type.
Content:
Input ID’s information, like domain name
www.ipsectest.com
.
Remote ID:
Type:
Specify Remote ID type.
Identifier:
Input remote ID’s information, like domain name
www.ipsectest.com
.
SA Lifetime:
Specify the number of minutes that a Security Association (SA) will stay active before new
encryption and authentication key will be exchanged. There are two kinds of Security Associations: IKE and
IPSec. IKE negotiates and establishes SA on behalf of IPSec.
Phase 1 (IKE):
To issue an initial connection request for a new VPN tunnel. The range can be from
5 to 15,000 minutes, and the default is 240 minutes.
Phase 2 (IPSec):
To negotiate and establish secure authentication. The range can be from 5 to
15,000 minutes, and the default is 60 minutes.
A short SA time increases security by forcing the two parties to update the keys. However, every time the
VPN tunnel re-negotiates, access through the tunnel will be temporarily disconnected.
Ping for Keep Alive:
It is used to detect IPSec tunnel connection failure. Connection failure is defined as
abort or in NO response state. In such event Ping to Keep Alive takes proper action to ensure the
connection quality of the IPSec.
PING to the IP:
It is able to IP Ping the remote PC with the specified IP address and alert when the
connection fails. Once alter message is received, Gateway will drop this tunnel connection. Default setting
is 0.0.0.0, which disables the function.
Interval:
This sets the time interval between
Pings to the IP
function to monitor the connection status.
Default interval setting is 10 seconds. Time interval can be set from 0 to 3600 second, 0 second disables
the function.
Ping to the IP
Internal (sec)
Ping to the IP Action
0.0.0.0
0
No
0.0.0.0
2000
No
xxx.xxx.xxx.xxx
(A valid IP Address)
0
No
xxx.xxx.xxx.xxx
(A valid IP Address)
2000
Yes, activate it in every 2000
second.
Содержание 8860-C1
Страница 1: ...Version 5 51 r1 Last Revised 10 10 2007 ADSL 2 Gateway 8860 C1 User s Manual...
Страница 5: ......
Страница 13: ......
Страница 28: ...Chapter 4 Configuration 27...
Страница 83: ...Chapter 4 Configuration 82 Example Configuring a IPSec Host to LAN VPN Connection...
Страница 125: ......