Chapter 6 IP security and VPN
169
Using the BayStack Instant Internet Management Software Version 7.11
Contivity version 2.6 has also implemented aggressive mode for
non-contivity clients, in order to support more client implementations. Instant
Internet leverages this new capability to act as a single-user client on behalf of
the network (many-to-one NAT).
Using perfect forward secrecy
Perfect forward secrecy (PFS) means that the compromise of a single key only
permits access to data protected by that key. PFS has been added primarily for
easy compatibility with Contivity.
The PFS setting between the Instant Internet unit and the Contivity CES must
match. The Instant Internet unit responds to a phase 2 key exchange performed
by the destination regardless of this setting. Note that PFS also incurs significant
additional computational overhead that you may want to avoid unless you
understand the security implications and PFS is required.
The default setting for PFS depends on whether you add an IPsec to tunnel to
another Instant Internet or Contivity. The default when connecting to another
Instant Internet unit is off. The default when connecting to Contivity is on.
To enable PFS:
1
Start Setup, and if prompted, select a unit to configure.
2
In the Interfaces area, select the IPsec interface for which you want to modify
the PFS.
3
Click Configure.
The IPsec Configuration dialog box opens
(Figure 85)
.
Содержание 400
Страница 16: ...16 Contents 300868 G ...
Страница 22: ...22 Figures 300868 G ...
Страница 24: ...24 Tables 300868 G ...
Страница 92: ...92 Chapter 2 User access administration 300868 G ...
Страница 114: ...114 Chapter 3 Internet activity logging 300868 G ...
Страница 166: ...166 Chapter 5 Advanced IP configuration 300868 G ...
Страница 200: ...200 Chapter 6 IP security and VPN 300868 G ...
Страница 256: ...256 Chapter 8 Advanced communications configuration 300868 G ...
Страница 302: ...302 Chapter 10 Instant Internet unit configuration support and diagnostics 300868 G ...
Страница 314: ...314 Appendix A Troubleshooting and error messages 300868 G ...
Страница 344: ......