6: Network Settings
PremierWave® Intelligent Gateway User Guide
55
Mode Configuration
Click to enable or disable extended authentication operation and the
settings provided to the client during the configuration exchange.
Type
Select the VPN type:
Tunnel
- Tunnel mode is used for protecting traffic between networks,
when traffic must pass through intermediate, untrusted network.
Transport
- Transport mode is used for end-to-end communication (for
example, for communications between a client and a server).
Interface
Select the interface to use to connect to VPN Gateway.
REMOTE NETWORK
Endpoint
Enter the remote VPN gateway’s IP address.
Subnet
Enter the subnet behind the VPN gateway.
ID
Specify the identifier through which to receive from the remote host during
Phase 1 negotiation.
Router/Next Hop
Enter the next-hop gateway IP address for the VPN gateway.
LOCAL NETWORK
Subnet
Define which local devices have access to or can be accessed from the
VPN connection.
ID
Specify the identifier sent to the remote host during Phase 1 negotiation.
Router/Next Hop
Enter the next-hop gateway IP address for our connection to the public
network.
KEY MANAGEMENT
Perfect Forward Secrecy
(PFS)
Select to enable or disable whether Perfect Forward Secrecy of keys is
desired on the connection's keying channel. Enabling this feature will
require IKE to generate a new set of keys in Phase 2 rather than using the
same key generated in Phase 1.
Pre-shared key (PSK)
Enter the pre-shared key to be used in the IPSec setting between the Local
and VPN Gateway.
ISAKMP PHASE 1 (IKE)
Aggressive Mode
Select to enable or disable Aggressive Mode. In Aggressive mode, IKE tries
to combine as much information into fewer packets while maintaining
security. Aggressive mode is slightly faster but less secure.
NAT Traversal
Select to enable or disable NAT Traversal. If there is an external NAT
device between VPN tunnels, the user must enable NAT Traversal.
Encryption
Select the encryption algorithm in key exchange.
Authentication
Select the hash algorithm in key exchange.
DH Group
Select the Diffie-Hellman group (the Key Exchange group between the
Remote and VPN Gateways).
IKE Lifetime
Enter the lifetime, in hours, for IKE SA.
ISAKMP PHASE 2 (ESP)
Encryption
Select the encryption Algorithm in data exchange.
Authentication
Select the hash Algorithm in data exchange.
DH Group
Select the Diffie-Hellman groups (the Key Exchange group between the
Remote and VPN Gateways) for Phase 2.
SA Lifetime
Enter the lifetime, in hours, for SA in Phase 2.
VPN Settings
Description