Chapter 6 IP security and VPN
185
Using the BayStack Instant Internet Management Software Version 7.11
Instant Internet supports Perfect Forward Secrecy (PFS) for easy compatibility
with Contivity because Contivity, by default, has PFS enabled. When you use
Setup to configure a connection to Contivity, PFS is enabled on the Instant
Internet unit by default.
•
Instant Internet does not support 40-bit Data Encryption Standard (DES).
Instant Internet does support 56-bit encryption (DES) for VPN tunneling as a
standard feature. Instant Internet also supports 168-bit encryption (3DES) as
an add-on feature.
•
During phase 1 negotiations, CES requires single DES. If you wish to use
3DES, you must also select single DES for encryption type. Instant Internet
uses triple DES (3DES) for the actual tunneled data if it is configured as
higher priority than DES.
•
Instant Internet does not support compression. The fact that Instant Internet
does not support compression does not affect compression on the CES.
Compression may be enabled on the CES even though it is not supported on
Instant Internet.
Other issues
•
If you enable the Instant Internet unit as a DNS proxy server, the DNS
addresses configured in Instant Internet must be able to resolve all desired
host names, whether part of the public Internet, the private network, or
otherwise.
As an alternative, if Instant Internet clients are configured to use a DNS proxy
server other than the Instant Internet unit, they follow the rules for Microsoft
networking, which allows more flexibility in determining name resolution.
For more information, refer to your Microsoft networking documentation.
PFS incurs significant additional computational overhead that you may
want to avoid unless you understand the security implications and PFS is
required
Содержание 400
Страница 16: ...16 Contents 300868 G ...
Страница 22: ...22 Figures 300868 G ...
Страница 24: ...24 Tables 300868 G ...
Страница 92: ...92 Chapter 2 User access administration 300868 G ...
Страница 114: ...114 Chapter 3 Internet activity logging 300868 G ...
Страница 166: ...166 Chapter 5 Advanced IP configuration 300868 G ...
Страница 200: ...200 Chapter 6 IP security and VPN 300868 G ...
Страница 256: ...256 Chapter 8 Advanced communications configuration 300868 G ...
Страница 302: ...302 Chapter 10 Instant Internet unit configuration support and diagnostics 300868 G ...
Страница 314: ...314 Appendix A Troubleshooting and error messages 300868 G ...
Страница 344: ......