VPN advanced configuration
171
Configuration Guide
Users configuration
This section provides configuration information for the client tunnel.
Users configuration navigation
•
User database configuration parameters (page 171)
•
IP address pool configuration parameters (page 172)
•
VPN client termination configuration parameters (page 172)
User database configuration parameters
The following section describes the parameters for the configuration of users located at
Configuration, VPN, Users, User Database
tab
.
Authentication
Select the preferred authentication method.
Select None to indicates no authentication method is required.
Select HMAC-MAC5, the message authentication code is calculated using
the MD5 cryptographic hash function. This cryptographic hash function
has some additional security properties with a 128-bit hash value, which is
commonly used to check the integrity of files.
Select HMAC-SHA1, the message authentication code is calculated using
the SHA1 algorithm. This cryptographic hash function computes a
condensed digital representation to a high degree of probability.
IPSec Mode
Select the IPSec mode.
Select Tunnel, IPSec encrypts the IP header and the Payload.
Select Transport, IPSec encrypts only the Payload.
Preferred Forward Secrecy
Select the Preferred Forward Secrecy (PFS). Select one of the following
options:
•
Select None – IKE does not use any PFS.
•
PFS Group 1 – IKE uses a 768-bit Diffie-Hellman Prime modules
group for performing the new Diffie-Hellman exchange.
•
PFS Group 2 – IKE uses a 1024-bit Diffie-Hellman Prime modules
group for performing the new Diffie-Hellman exchange.
•
PFS Group 5 – IKE uses a 1536-bit Diffie-Hellman Prime modules
group for performing the new Diffie-Hellman exchange.
Life Time
Select the lifetime unit. It can be seconds, minutes, or hours.
The default value is seconds.
Life Time Value
Type the lifetime value.
The default value is 800 seconds.
Anti Replay
Displays the anti-replay status for the IKE pre-shared secret policy.
Displays one of the following:
•
ENABLE - anti-replay functionality is activated.
•
DISABLE - anti-replay functionality is deactivated.
The default value is ENABLE.
Variable
Value
Содержание BSG12aw 1.0
Страница 14: ...14 Introduction NN47928 500 NN47928 500 ...
Страница 22: ...22 WAN configuration NN47928 500 NN47928 500 ...
Страница 54: ...54 SIP configuration NN47928 500 NN47928 500 ...
Страница 80: ...80 QoS configuration NN47928 500 NN47928 500 ...
Страница 82: ...82 Advanced configuration NN47928 500 NN47928 500 ...
Страница 110: ...110 LAN advanced configuration NN47928 500 NN47928 500 ...
Страница 144: ...144 IP routing advanced configuration NN47928 500 NN47928 500 ...
Страница 152: ...152 DHCP advanced configuration NN47928 500 NN47928 500 ...
Страница 164: ...164 QoS advanced configuration NN47928 500 NN47928 500 ...
Страница 176: ...176 VPN advanced configuration NN47928 500 NN47928 500 ...
Страница 200: ...200 Port management advanced configuration NN47928 500 NN47928 500 ...