Page 118 SonicWALL TELE3 SP Administrator’s Guide
Enable Perfect Forward Secrecy
The
Enable Perfect Forward Secrecy
check box increases the renegotiation time of the VPN
tunnel. By enabling
Perfect Forward Secrecy
, a hacker using brute force to break encryption
keys is not able to obtain other or future IPSec keys. During the phase 2 renegotiation between
two SonicWALL appliances or a Group VPN SA, an additional Diffie-Hellman key exchange is
performed.
Enable
Perfect Forward Secrecy
adds incremental security between gateways.
Phase 2 DH Group
If
Enable Perfect Forward Secrecy
is enabled, select the type of Diffie-Hellman (DH) Key
Exchange (a key agreement protocol) to be used during phase 2 of the authentication process
to establish pre-shared keys. You can now select from three well-known DH groups:
•
Group 1
- less secure
•
Group 2
- more secure
•
Group 5
- most secure
Groups 1, 2, and 5 use Modular-Exponentiation with different prime lengths as listed below:
If network connection speed is an issue, select
Group 1
. If network security is an issue, select
Group 5
. To compromise between speed and security, select
Group 2
.
Default LAN Gateway
A
Default LAN Gateway
is used at a central site in conjunction with a remote site using the
Route all internet traffic through this SA
check box. The
Default LAN Gateway
field
allows the network administrator to specify the IP address of the default LAN route for incoming
IPSec packets for this SA.
Incoming packets are decoded by the SonicWALL and compared to static routes configured in
the SonicWALL. Since packets can have any IP address destination, it is impossible to configure
enough static routes to handle the traffic. For packets received via an IPSec tunnel, the
SonicWALL looks up a route for the LAN. If no route is found, the SonicWALL checks for a
Default LAN Gateway.
If a
Default LAN Gateway
is detected, the packet is routed through
the gateway. Otherwise, the packet is dropped.
Group
Descriptor
Prime Size
(bits)
1
768
2
1024
5
1536
Содержание TELE3 SP
Страница 1: ...SONICWALL The TELE3 SP Administrator s Guide...
Страница 204: ...Appendices Page 203 Notes...
Страница 205: ...Page 204 SonicWALL TELE3 SP Administrator s Guide...