Chapter 4: Configuration
86
the password before sending and also allows for challenges at different time to ensure that an intruder did
not compromise the client.
Idle Time
: Auto-disconnect the VPN connection when there is no activity on the connection for a
predetermined period of time. 0 means this connection is always on.
Active as default route
: Commonly used by the
Dial-out
connection that all packets are routed through the
VPN tunnel to the Internet. Activating this function may degrade the Internet performance.
Click
Apply
after changing settings.
L2TP over IPSec (L2TP/IPSec) VPN Connection
IPSec:
Enable to enhance your LT2P VPN security.
Authentication:
Authentication establishes the integrity of the datagram and ensures it is not tampered with
in transmit. There are three options: Message Digest 5 (
MD5
), Secure Hash Algorithm (
SHA1
) or
NONE
.
SHA1 is more resistant to brute-force attacks but slower than MD5.
MD5:
A one-way hashing algorithm that produces a 128
−
bit hash.
SHA1:
A one-way hashing algorithm that produces a 160
−
bit hash.
Encryption:
Select the encryption method from the pull-down menu. There are four options:
DES
,
3DES
,
AES
and
NONE
. NONE means it is a tunnel with no encryption. 3DES and AES are more powerful but
increase latency.
DES:
Stands for Data Encryption Standard, it uses 56 bits encryption method.
3DES:
Stands for Triple Data Encryption Standard, it uses 168 (56*3) bits encryption method.
AES:
Stands for Advanced Encryption Standards, it uses 128 bits encryption method.
Perfect Forward Secrecy:
Choose whether to enable PFS using Diffie-Hellman public-key cryptography to
change encryption keys during the second phase of VPN negotiation. This function will provide better
security but prolongs the VPN negotiation time. Diffie-Hellman is a public-key cryptography protocol that
allows two parties to establish a shared secret over an unsecured communication channel. There are three
modes: MODP 768-bit, MODP 1024-bit and MODP 1536-bit. MODP stands for Modular Exponentiation
Groups.
Pre-shared Key:
This is the Internet Key Exchange (IKE) protocol. Both sides should use the same key.
IKE is used to establish a shared security policy and authenticated keys for services (such as IPSec) that
require a key. Before any IPSec traffic can be passed, each gateway must be able to verify the identity of its
peer. This can be done by manually entering the pre-shared key into both sides (gateway or hosts).
Remote Host Name (Optional):
Enter the hostname for the remote VPN device. If remote hostname
matches, tunnel will be connected; otherwise, it will be dropped.
Cautious:
This is only when the gateway performs as a VPN server. This option should only be used by advanced
users.
Local Host Name (Optional):
Enter the hostname of the Local VPN device that have established a VPN
tunnel. The Gateway’s default Hostname is
home.gateway.
Tunnel Authentication:
This enables the gateway to authenticate both the L2TP remote and the L2TP
host. This is only valid when the L2TP remote supports this feature.
Содержание 8860-C1
Страница 1: ...Version 5 51 r1 Last Revised 10 10 2007 ADSL 2 Gateway 8860 C1 User s Manual...
Страница 5: ......
Страница 13: ......
Страница 28: ...Chapter 4 Configuration 27...
Страница 83: ...Chapter 4 Configuration 82 Example Configuring a IPSec Host to LAN VPN Connection...
Страница 125: ......