Page 150 SonicWALL TELE3 SP Administrator’s Guide
•
Phase 2 DH Group
•
Default LAN Gateway
Use Aggressive Mode
Selecting the
Use Aggressive Mode
check box forces the SonicWALL appliance to use
Aggressive Mode to establish the VPN tunnel even if the SonicWALL has a static IP address.
Aggressive Mode requires half of the main mode messages to be exchanged in Phase One of
the SA exchange.
Use Aggressive Mode
is useful when the SonicWALL is located behind
another NAT device. The check box is only available if
IKE using Pre-shared Secret
or
IKE
using certificates
(SonicWALL to SonicWALL) is selected as the
IPSec Keying Mode
.
Enable Keep Alive
Selecting the
Enable Keep Alive
check box allows the VPN tunnel to remain active or maintain
its current connection by listening for traffic on the network segment between the two
connections. Interruption of the signal forces the tunnel to renegotiate the connection.
Require authentication of VPN clients via XAUTH
An IKE Security Association can be configured to require XAUTH authentication before allowing
VPN clients to access LAN resources. XAUTH authentication provides an additional layer of VPN
security while simplifying and centralizing management. XAUTH authentication allows many
VPN clients to share the same VPN configuration, but requires each client to authenticate with
a unique user name and password.
Require authentication of local users
Selecting this checkbox requires that all outbound VPN traffic using this SA is from an
authenticated user. Unauthenticated traffic is not allowed on the VPN tunnel.
Require authentication of remote users
Selecting this checkbox requires that all inbound VPN traffic using this SA is from an
authenticated user. Unauthenticated traffic not allowed on the VPN tunnel. Select
Remote
Users behind VPN gateway
if remote users have a VPN tunnel that terminates on the VPN
gateway. Select
Remote VPN Clients with XAUTH
if remote users require authentication
using XAUTH and are accessing the SonicWALL via a VPN Client.
Enable Windows Networking (NetBIOS) broadcast
Computers running Microsoft Windows
®
communicate with one another through NetBIOS
broadcast packets. Select the
Enable Windows Networking (NetBIOS) broadcast
check
box to access remote network resources by browsing the Windows
®
Network Neighborhood.
Содержание TELE3 SP
Страница 1: ...SONICWALL The TELE3 SP Administrator s Guide...
Страница 204: ...Appendices Page 203 Notes...
Страница 205: ...Page 204 SonicWALL TELE3 SP Administrator s Guide...