VPN configuration
61
Configuration Guide
IPSec Authentication
Select the preferred authentication method. Select one of the following
options:
•
HMAC-MAC5 - the message authentication code is calculated using
the MD5 cryptographic hash function. This cryptographic hash function
has some additional security properties with a 128-bit hash value,
which is commonly used to check the integrity of files.
•
HMAC-SHA1 - the message authentication code is calculated using
the SHA1 algorithm. This cryptographic hash function computes a
condensed digital representation to a high degree of probability.
DH Group
Select the required Diffie-Hellman (DH) group. DH key exchange is used
to establish preshared keys. Select one of the following:
•
Group 1 – IKE uses a 768-bit Diffie- Hellman Prime modules group for
performing the new Diffie-Hellman exchange.
•
Group 2 – IKE uses a 1024-bit Diffie- Hellman Prime modules group
for performing the new Diffie-Hellman exchange.
•
Group 5 – IKE uses a 1536-bit Diffie- Hellman Prime modules group
for performing the new Diffie-Hellman exchange.
Select Group 2 for a compromise between network speed and network
security.
Life Time
Select the life time unit. Select one of seconds, minutes, or hours.
Life Time Value
Type the life time value.
The range is 5 minutes to 8 hours.
Peer Identity Type/Value
Select the identity type to access the remote network. Select one of the
following:
•
IPV4 - IP address
•
FQDN - Fully Qualified Domain Name
•
EMAIL - email address of the user
•
KEYID - uniquely identifies the peer
Select the associated value from the list. The list contains the Remote
Identity values entered on VPN Global Settings.
Local Identity Type/Value
Select the identity type to access the local network. Select one of the
following:
•
IPV4 - IP address
•
FQDN - Fully Qualified Domain Name
•
EMAIL - email address of the user
•
KEYID - uniquely identifies the peer
Type the associated value.
Traffic Selector table
Local Address
Type the Source IP address of the outbound traffic.
Local Address Mask
Type the Network mask of the outbound traffic.
Remote Address
Type the Destination IP address of the outbound traffic.
Remote Address Mask
Type the Destination mask of the outbound traffic.
Variable
Value
Содержание BSG12aw 1.0
Страница 14: ...14 Introduction NN47928 500 NN47928 500 ...
Страница 22: ...22 WAN configuration NN47928 500 NN47928 500 ...
Страница 54: ...54 SIP configuration NN47928 500 NN47928 500 ...
Страница 80: ...80 QoS configuration NN47928 500 NN47928 500 ...
Страница 82: ...82 Advanced configuration NN47928 500 NN47928 500 ...
Страница 110: ...110 LAN advanced configuration NN47928 500 NN47928 500 ...
Страница 144: ...144 IP routing advanced configuration NN47928 500 NN47928 500 ...
Страница 152: ...152 DHCP advanced configuration NN47928 500 NN47928 500 ...
Страница 164: ...164 QoS advanced configuration NN47928 500 NN47928 500 ...
Страница 176: ...176 VPN advanced configuration NN47928 500 NN47928 500 ...
Страница 200: ...200 Port management advanced configuration NN47928 500 NN47928 500 ...