the PKI server mode the router represents the Certificate Authority and issues the certificates
for remote peers.
Negotiation mode:
Choose the negotiation mode (main, aggressive). The aggressive
mode has to be used when dealing with dynamic endpoint ad-
dresses, but it is referred to be less secure compared to the main
mode as it reveals your identity to an eavesdropper.
Encryption algorithm:
The IKE encryption method (3DES, AES128, AES192, AES256)
Authentication algorithm:
The IKE authentication method (MD5, SHA1, SHA2-256)
IKE Diffie-Hellman group:
The IKE Diffie-Hellman group (2, 5 and 16-21)
SA life time:
The Security Association lifetime
Perfect forward secrecy (PFS):
This feature heavily increases security as PFS avoids penetration
of the key-exchange protocol and prevents compromising the keys
negotiated earlier.
Using Public Key Infrastructure requires similar settings, but the Operation mode must be configured.
Operation mode
Mode can be set either to "server" or "client". As a "server" and once you have successfully set up an
IPsec tunnel, you can manage and enable clients connecting to your service. It is possible to generate
and download expert mode files for enabled clients which can be used to easily populate each client.
IPsec Proposal
Encapsulation mode:
Only the tunnel encapsulation mode is enabled
IPsec protocol:
Only the ESP IPsec protocol is enabled
Encryption algorithm:
The IKE encryption method (3DES, AES128, AES192, AES256,
blowfish128, 192 and 256)
97
© RACOM s.r.o. – M!DGE2 GPRS/UMTS/HSPA+/LTE router
Web Configuration
Содержание M!DGE2
Страница 2: ......
Страница 159: ...7 8 LOGOUT Log out from Web Manager 159 RACOM s r o M DGE2 GPRS UMTS HSPA LTE router Web Configuration ...
Страница 188: ...188 ...