170
VPN advanced configuration
NN47928-500
NN47928-500
DH Group
Select the required Diffie-Hellman (DH) group. DH key exchange is used
to establish preshared keys.
Select Group 1 – IKE uses a 768-bit Diffie- Hellman Prime modules group
for performing the new Diffie-Hellman exchange.
Select Group 2 – IKE uses a 1024-bit Diffie- Hellman Prime modules
group for performing the new Diffie-Hellman exchange.
Select
Group 5 – IKE uses a 1536-bit Diffie- Hellman Prime modules
group for performing the new Diffie-Hellman exchange.
Exchange
Select the exchange mode.
Select Main for the highest level of Security.
Select Aggressive for speed.
The default value is Main.
Life Time
Select the lifetime unit. It can be seconds, minutes, or hours.
Life Time Value
Type the lifetime value.
Peer Identity Type/Value
Select the identity type to access the remote network. Select one of the
following:
•
IPV4 - IP address
•
FQDN - Fully Qualified Domain Name
•
EMAIL - email address of the user
•
KEYID - uniquely identifies the peer
Select the associated value from the list. The list contains the Remote
Identity values added on VPN Global Settings.
Local Identity Type/Value
Select the identity type to access the local network. Select one of the
following:
•
IPV4 - IP address
•
FQDN - Fully Qualified Domain Name
•
EMAIL - email address of the user
•
KEYID - uniquely identifies the peer
Type the associated value.
IP Sec Phase 2 Proposal table
Protocol
Select the authentication protocol.
Select
ESP, IPSec encrypts and authenticates.
Select AH, IPSec only authenticates.
Encryption
Select the IPSec Encryption. Select one of the following options:
•
null – indicates no standard is used for IPsec encryption.
•
Data Encryption Standard (DES) – indicates a standard for encrypting
data that uses a 64 bit key to encrypt data, but only 56 bits are usable.
This standard is considered inadequate for data protection as this
standard do not match the speed of computer.
•
Triple Data Encryption Standard (3DES) – processes each block of
data using a different key each time resulting in a significantly more
secure message.
•
Advanced Encryption Standard (AES-128, AES-192, AES-256) – has
a fixed block size of 128 bits and a key size of 128, 192 or 256 bits.
Due to the fixed block size of 128 bits, AES operates on a 4x4 array of
bytes.
Variable
Value
Содержание BSG12aw 1.0
Страница 14: ...14 Introduction NN47928 500 NN47928 500 ...
Страница 22: ...22 WAN configuration NN47928 500 NN47928 500 ...
Страница 54: ...54 SIP configuration NN47928 500 NN47928 500 ...
Страница 80: ...80 QoS configuration NN47928 500 NN47928 500 ...
Страница 82: ...82 Advanced configuration NN47928 500 NN47928 500 ...
Страница 110: ...110 LAN advanced configuration NN47928 500 NN47928 500 ...
Страница 144: ...144 IP routing advanced configuration NN47928 500 NN47928 500 ...
Страница 152: ...152 DHCP advanced configuration NN47928 500 NN47928 500 ...
Страница 164: ...164 QoS advanced configuration NN47928 500 NN47928 500 ...
Страница 176: ...176 VPN advanced configuration NN47928 500 NN47928 500 ...
Страница 200: ...200 Port management advanced configuration NN47928 500 NN47928 500 ...