36
value ranges from 300 seconds to 172,800 seconds.
Encapsulation Protocol
There are three protocols can be selected: ESP, AH and ESP+AH.
pfs:
Perfect Forward Secrecy (PFS), allow IKE to re-exchange a key for IPSec instead of direct use
ISAKMP key as the IPSec key during phase 2 of IKE negotiation. The ISAKMP key is derived at the
end of phase 1 of IKE negotiation. This setting must be same between initiator and responder or a VPN
tunnel can not be created.
Aggressive mode:
During phase 1 of IKE negotiation, IKE operates in main mode or aggressive mode. Aggressive mode
is a reduced version of main mode and more unsafe.
Pre-shared key
It is the first key that supports IKE mechanism of both VPN gateways for negotiating further security
keys. The pre-shared key must be same for both end gateways.
Remote ID
It is optional. Some VPN gateways require ID for authentication. For example, to connect to
SonicWall
VPN gateway, user should input
serial number
here. But to connect to
Cisco
VPN gateway, user
should input
IP@domain
.
Local ID
It is optional. Some VPN gateways require local ID for authentication. For example, NetScreen VPN
router serves as the initiator and can inquire if the responder is specific gateway or host that should be
dedicated by the local ID.
Содержание FBR-1411TX
Страница 1: ...1 LevelOne FBR 1411TX 1W 4L High Performance Broadband Router w VPN DMZ port User s Manual...
Страница 46: ...46 After configure Rule 1 Schedule Enable Selected if you want to Enable the Scheduler Edit...
Страница 48: ...48 Exanple2 Packet Filter Apply Rule 1 ftp time everyday 14 10 to 16 20 4 8 Toolbox Chapter Home...
Страница 56: ...56...