Chapter 4
Advanced Configuration
41
10/100 8-Port VPN Router
Remote Security Group Type > IP
IP address
Enter the appropriate IP address.
Subnet
The default is
Subnet
. All computers on the remote subnet
will be able to access the tunnel.
Remote Security Group Type > Subnet
IP address
Enter the IP address.
Subnet Mask
Enter the subnet mask. The default is
255.255.255.0
.
IP Range
Specify a range of IP addresses within a subnet that will be
able to access the tunnel.
Remote Security Group Type > IP Range
IP range
Enter the range of IP addresses.
IPSec Setup
In order for any encryption to occur, the two ends of a
VPN tunnel must agree on the methods of encryption,
decryption, and authentication. This is done by sharing
a key to the encryption code. For key management, the
default mode is
IKE with Preshared Key
.
Keying Mode
Select
IKE with Preshared Key
or
Manual
.
Both ends of a VPN tunnel must use the same mode of
key management. After you have selected the mode, the
settings available on this screen may change, depending
on the selection you have made. Follow the instructions
for the mode you want to use.
IKE with Preshared Key
IKE is an Internet Key Exchange protocol used to negotiate
key material for Security Association (SA). IKE uses the
Preshared Key to authenticate the remote IKE peer.
Phase 1 DH Group
Phase 1 is used to create the SA. DH
(Diffie-Hellman) is a key exchange protocol used during
Phase 1 of the authentication process to establish pre-
shared keys. There are three groups of different prime
key lengths. Group 1 is 768 bits, and Group 2 is 1,024 bits.
Group 5 is 1,536 bits. If network speed is preferred, select
Group 1
. If network security is preferred, select
Group 5
.
Phase 1 Encryption
Select a method of encryption:
DES
(56-bit),
3DES
(168-bit),
AES-128
(128-bit),
AES-192
(192-bit), or
AES-256
(256-bit). The method determines
the length of the key used to encrypt or decrypt ESP
packets. AES-256 is recommended because it is more
secure. Make sure both ends of the VPN tunnel use the
same encryption method.
Phase 1 Authentication
Select a method of
authentication,
MD5
or
SHA
. The authentication method
determines how the ESP packets are validated. MD5 is
a one-way hashing algorithm that produces a 128-bit
digest. SHA is a one-way hashing algorithm that produces
a 160-bit digest. SHA is recommended because it is more
secure. Make sure both ends of the VPN tunnel use the
same authentication method.
Phase 1 SA Life Time
Configure the length of time a VPN
tunnel is active in Phase 1. The default value is
28800
seconds.
Perfect Forward Secrecy
If the Perfect Forward Secrecy
(PFS) feature is enabled, IKE Phase 2 negotiation will
generate new key material for IP traffic encryption and
authentication, so hackers using brute force to break
encryption keys will not be able to obtain future IPSec
keys.
Phase 2 DH Group
If the Perfect Forward Secrecy feature
is disabled, then no new keys will be generated, so you do
not need to set the Phase 2 DH Group (the key for Phase 2
will match the key in Phase 1).
There are three groups of different prime key lengths.
Group 1 is 768 bits, and Group 2 is 1,024 bits. Group 5 is
1,536 bits. If network speed is preferred, select
Group 1
.
If network security is preferred, select
Group 5
. You do
not have to use the same DH Group that you used for
Phase 1.
Phase 2 Encryption
Phase 2 is used to create one or
more IPSec SAs, which are then used to key IPSec sessions.
Select a method of encryption:
NULL
,
DES
(56-bit),
3DES
(168-bit),
AES-128
(128-bit),
AES-192
(192-bit), or
AES-256
(256-bit). It determines the length of the key used to
encrypt or decrypt ESP packets. AES-256 is recommended
because it is more secure. Both ends of the VPN tunnel
must use the same Phase 2 Encryption setting.
Phase 2 Authentication
Select a method of
authentication,
NULL
,
MD5
, or
SHA
. The authentication
method determines how the ESP packets are validated.
MD5 is a one-way hashing algorithm that produces a
128-bit digest. SHA is a one-way hashing algorithm that
produces a 160-bit digest. SHA is recommended because
it is more secure. Both ends of the VPN tunnel must use
the same Phase 2 Authentication setting.
Phase 2 SA Life Time
Configure the length of time a VPN
tunnel is active in Phase 2. The default is
3600
seconds.