Certificate Authority and imported to the router after-
wards. In the PKI server mode the router represents the
Certificate Authority and issues the certificates for remote
peers.
Negotiation mode:
Choose the negotiation mode (main, aggressive). The aggressive
mode has to be used when dealing with dynamic endpoint ad-
dresses, but it is referred to be less secure compared to the main
mode as it reveals your identity to an eavesdropper.
Encryption algorithm:
The IKE encryption method (3DES, AES128, AES192, AES256)
Authentication algorithm:
The IKE authentication method (MD5, SHA1, SHA2-256)
IKE Diffie-Hellman group:
The IKE Diffie-Hellman group (2, 5 and 16-21)
SA life time:
The Security Association lifetime
Perfect forward secrecy (PFS):
This feature heavily increases security as PFS avoids penetration
of the key-exchange protocol and prevents compromising the keys
negotiated earlier.
Using Public Key Infrastructure requires similar settings, but the Operation mode must be configured.
Operation mode
Mode can be set either to "server" or "client". As a "server" and once you have successfully set up an
IPsec tunnel, you can manage and enable clients connecting to your service. It is possible to generate
and download expert mode files for enabled clients which can be used to easily populate each client.
MG102iGPRS/UMTS/HSPA+/LTE router – © RACOM s.r.o.
94
Web Configuration
Содержание MG102i
Страница 2: ......
Страница 147: ...147 RACOM s r o MG102iGPRS UMTS HSPA LTE router Web Configuration...
Страница 148: ...7 8 LOGOUT Log out from Web Manager MG102iGPRS UMTS HSPA LTE router RACOM s r o 148 Web Configuration...
Страница 174: ...174...