background image

 

 

 

 

 

 

 

 

  

 

© Copyright 2012 TRENDnet. All Rights Reserved. 

 

 

 

 
TRENDnet User’s Guide

 

TW100-BRV214 

69

 

Additional IPsec VPN options 

There are additional parameters in your router that you can configure to increase the 

encryption or authentication strength of the IPsec VPN Tunnel. Any additional security 

options enabled and configured must be configured on both sides of the IPsec VPN 

tunnel. Adding additional security strength to your VPN may significantly degrade the 

performance of transmitting or receiving data through the VPN tunnel. 
 

 

 

Method –

 You can choose between 

IKE 

or 

Manual

o

 

IKE (Internet Key Exchange)

 –  (Recommended) Compared to the 

older Manual method, this method is more secure as it can provide 

endpoint security, security against replay attacks or anti-replay, and 

dynamic session rekeying using a PSK (preshared key) meaning that 

the session key between the two endpoints will change after a 

specified period of time. 

o

 

Manual 

– Manual Key is an older with several limitations compared to 

IKE. Since the same session key is always used and never changes, the 

VPN is vulnerable to replay attacks. 
 

 

 

Phase 1/Phase 2 Key Life Time

 – Using the IKE method, you can specify the 

period of time in seconds for each phase of the tunnel before a new session 

key is created between the VPN endpoints.  There is an SA (security 

association) created for each phase, one for Phase 1 (IKE phase) phase and 

another for Phase 2 (IPsec phase). It is recommended that these values are left 

at default settings. 

Note: If you are changing these values, it is strongly recommended to have 

different time values for each, never the same and assign a longer time value to 

Phase 1 than Phase 2. Assigning the same value may cause VPN connectivity 

problems between the VPN endpoints.

  

 
 

 

 

Encapsulation Protocol -

 You can choose between 

ESP, AH, or ESP+AH

o

 

ESP (Encapsulating Security Payload) 

– (Recommended) This protocol 

is recommended as it can provide both authentication and encryption 

of the data and maintain and acceptable performance. 

o

 

AH (Authentication Header) 

– This protocol is less secure compared to 

ESP as it can only provide authentication of the data, no encryption. 

o

 

ESP+AH

 

(Encapsulating Security P Authentication Header) 

– 

This protocol is the most secure because it combines the security 

mechanism of both ESP and AH, however, performance may degrade 

significantly if used due to the additional security encapsulation of 

both protocols. 
 

 

 

PFS (Perfect Forward Secrecy) Group 

– You can choose between 

Group 1

Group 2

Group 5

, or 

Same Phase 1

. This provides an additional layer of 

security in Phase 2 (IPsec phase) by ensuring that if any session keys are 

compromised, no other keys can be derived from the compromised key. The 

group options are based of a security algorithm known as the DH (Diffie-

Hellman) algorithm. As the DH group numbers increase, the security also 

increases. Adding this option may significantly decrease performance. 

o

 

Group 1 – 

DH group 1 (768-bit) 

o

 

Group 2 – 

DH group 2 (1024-bit) 

o

 

Group 5 – 

DH group 5 (1536-bit) 

o

 

Same as Phase 1

 – Chooses the same DH group selected under the IKE 

proposal section. 
 

 

 

Aggressive Mode –

By default, the IKE negotiation will use Main mode. 

Checking this option will change negotiation to Aggressive. Aggressive mode 

will increase the speed of establishing a connection between the VPN 

endpoints by sending fewer messages than in Main mode. The disadvantage of 

Содержание TW100-BRV214

Страница 1: ...TRENDnet User s Guide Cover Page...

Страница 2: ...l 31 URL Filters 32 Keyword Blocking 33 Packet Outbound Inbound Filters 33 Advanced Router Setup 36 Access your router management page 36 Change your router login password 36 Set your router date and...

Страница 3: ...y defaults 55 Router Default Settings 55 Backup and restore your router configuration settings 56 Upgrade your router firmware 57 Restart your router 58 Check connectivity using the router management...

Страница 4: ...and packet filtering 4 x 10 100 Mbps Auto MDIX LAN ports 1 x 10 100 Mbps WAN port Internet On off button Compatible with most popular cable DSL Internet service providers using Dynamic Static IP PPPoE...

Страница 5: ...rdware Features Rear Panel View LAN Ports Connect Ethernet cables also called network cables from your router LAN ports and to your wired network devices WAN Port Connect an Ethernet cable also called...

Страница 6: ...lly with an Ethernet cable also called network cable The LED indicator will be blinking green while data is transmitted or received through the WAN port of your router LAN 1 4 Link Activity These LED...

Страница 7: ...computers are connected to the four LAN ports of the router using Ethernet cables also called network cables allowing these computers to access the Internet The router is also configured as a Virtual...

Страница 8: ...dditional switch to add more wired connections How to set up a home network 1 For a network that includes Internet access you ll need Computers devices with an Ethernet port also called network port A...

Страница 9: ...NS Server Address 1 _____ _____ _____ _____ DNS Server Address 2 _____ _____ _____ _____ 3 PPPoE to obtain IP automatically User Name _________ Password ________________ 4 PPPoE with a fixed IP addres...

Страница 10: ...ne end of a network cable to your router WAN port Connect the other end of the network cable to your Cable modem network port 5 Connect one end of a network cable to one of your router LAN ports 1 4 C...

Страница 11: ...option is selected and then click Enter Note If the Setup Wizard does not automatically appear click Wizard at the top of the page 4 Click Next 5 Enter the Old Password Default admin enter a New Pass...

Страница 12: ...lick Next 8 Configure the settings based on information provided by your Internet Service Provider ISP Follow the wizard instructions to complete your configuration Note Each Internet connection type...

Страница 13: ...lying the settings 12 Please wait until the router applies the changes and reboots Note If you checked the option to run network testing Internet connection test you will see the status message below...

Страница 14: ...AN ports labeled 1 2 3 4 on your router Check the status of the LED indicators 1 2 3 or 4 on the front panel of your router to ensure the physical cable connection from your computer or device Note If...

Страница 15: ...N only however both server mode and client mode are supported on your router Most computer operating systems already include a pre installed PPTP VPN client software that can be easily configured whic...

Страница 16: ...ke sure the LAN IP network on each VPN router is different Note Changing the LAN IP address of your router will change the LAN IP network of your router See page 39 for changing the LAN IP address Exa...

Страница 17: ...0 20 Note If the remote router is using dynamic DNS you can enter domain for the remote gateway instead of the WAN IP address Based on the example the network settings will be the following 7 Next to...

Страница 18: ...n IPsec VPN configuration page VPN Router A Tunnel Status VPN Router B Configuration 1 Log into your router management page see Access your router management page on page 36 Note If you changed router...

Страница 19: ...e the network settings will be the following 7 Next to Preshare Key enter the preshared key for your IPsec tunnel Note The preshared key entered must be the same as the preshared key configured in VPN...

Страница 20: ...N client computer If the single client computer is connecting to the Internet through a router with NAT enabled make sure the LAN IP network of the router NAT enabled is different from the LAN IP netw...

Страница 21: ...must be the same as the preshared key configured in VPN Router A Note The preshared key can consist of alphanumeric characters a b C 1 2 etc 9 Click the PFS Group drop down list and select Same as Pha...

Страница 22: ...g VPN PPTP Server To configure your router to allow PPTP VPN connections from remote VPN client computers or devices Typically the single client computer is connecting to the Internet through a router...

Страница 23: ...range e g 192 168 10 100 6 Next to Authentication Protocol check MS_CHAP and MS_CHAPv2 7 Next to MPPE Encryption Mode check the Enable option 8 Next to Encryption Length to ensure highest compatibilit...

Страница 24: ...the Status page See page 59 for checking the status page Example VPN Router A WAN Internet IP Address 10 10 10 10 VPN Router B WAN Internet IP Address 10 10 10 20 Make sure the LAN IP network on each...

Страница 25: ...nter the User Name and Password used by PPTP VPN clients to authenticate Note The same account can be used by multiple PPTP VPN clients 10 Click Save at the bottom of the page to save the changes Note...

Страница 26: ...255 255 0 subnet mask Connect The mode which the VPN tunnel should be connected o On demand Recommended This mode will connect only when the traffic is sent through VPN tunnel and disconnect automati...

Страница 27: ...168 100 1 255 255 255 0 Ensure that your router is connected to the Internet and computers and devices are able to access the Internet through your router and make note of the WAN Internet IP assigned...

Страница 28: ...n Status You can click Disconnect to disconnect the L2TP VPN client Client Server VPN Client Mode Configuration Security Setting VPN L2TP Client Your router can be configured as a L2TP VPN client to c...

Страница 29: ...anged your LAN IP settings or DHCP server range then you can leave hese settings at default Router default DHCP server range 192 168 10 101 192 168 10 199 IP Pool Start Address Changes the starting ad...

Страница 30: ...e Enable option to enable the L2TP client 4 Review the settings below Name Enter a name for the tunnel e g Tunnel 1 Peer IP Domain The remote WAN Internet IP address of your remote VPN router e g 10 1...

Страница 31: ...tus click Connect to connect the L2TP VPN client You can also click Disconnect to disconnect the L2TP VPN client GRE Generic Routing Encapsulation Tunneling Site to Site GRE Tunnel Configuration Secur...

Страница 32: ...ill also need to be entered when configuring Router B The preshared key can consist of up to five alphanumeric characters a b C 1 2 etc TTL Enter the Time to Live value Range 1 255 Recommended 100 Sub...

Страница 33: ...gly recommended to enter your own key Write down the key you enter as it will also need to be entered when configuring Router B The preshared key can consist of up to five alphanumeric characters a b...

Страница 34: ...ine which MAC addresses you do not want to allow access To simplify configuration click the DHCP clients drop down list to select and computer or device that is currently connected to your router Once...

Страница 35: ...o block access Drop Checking the option will drop or block access to the specific URL or domain Log Checking the option will log the access requests to the specific URL or domain in the router log Not...

Страница 36: ...to allow deny sources or Internet IP addresses to your network from the Internet or from computers or devices on your network to the Internet Firewall rules may allow for more granular control of spe...

Страница 37: ...configured correct and you have defined a schedule See page 37 to configure Time Settings and see page 51 to create a schedule To save changes click Save at the bottom of the page Note If you would li...

Страница 38: ...can select Both to choose both protocol types Enable Check the option to enable the filter Use rule Click the drop down list to select a pre defined schedule The filter will only be active during the...

Страница 39: ...ystem Password admin Change your router login password Configuration Basic Setting Password 1 Log into your router management page see Access your router management page on page 36 2 Click on Configur...

Страница 40: ...erver You can choose Auto to set the router to automatically select a predefined time server or Manual to manually enter a time server e g pool ntp org that is not listed Note If you do not choose Man...

Страница 41: ...cess of a new MAC address with your ISP then you can clone the address assign the registered MAC address of your previous device to your new router If you want to use the MAC address from the previous...

Страница 42: ...enter the router IP address settings IP Address Enter the new router IP address e g 192 168 100 1 Subnet Mask Enter the new router subnet mask e g 255 255 255 0 Note The DHCP address range will chang...

Страница 43: ...or devices e g trendnet com Note The DHCP lease time is the amount of time a computer or device can keep an IP address assigned by the DHCP server When the lease time expires the computer or device w...

Страница 44: ...DHCP client device to be allowed under the MAC Address Control configuration page Deny Enables the MAC Address Control feature and adds the selected DHCP client device to be denied under the MAC Addr...

Страница 45: ...to save the changes Note If you would like to discard the changes click Undo before you click Save If you click Back this will return you to the main DHCP Server page Enable disable UPnP on your rout...

Страница 46: ...VPN protocol to turn on the VPN pass through feature Note It is recommended to leave these settings enabled 4 To save changes click Save at the bottom of the page Note If you would like to discard the...

Страница 47: ...before you click Save Allow deny ping requests to your router from the Internet Configuration Security Setting Management To provide additional security you may want to disable your router from respo...

Страница 48: ...our router management page see Access your router management page on page 36 3 Click on Configuration at the top of the page click on Advanced Setting and click on Dynamic DNS 4 Next to DDNS click Ena...

Страница 49: ...R notation Enter the subnet mask in CIDR Classless Inter Domain Routing notation for IP address or IP network you would like to allow For example if you are specifying a single IP address use 32 which...

Страница 50: ...guration Basic Setting Network Settings Virtual Computers If you have multiple static WAN Internet IP addresses assigned by your ISP Internet Service Provider you can map these WAN Internet IP address...

Страница 51: ...can choose to manually add a new virtual server 3 Review the virtual server settings Server IP Enter the IP address of the device to forward the port e g 192 168 10 101 Note You should assign a stati...

Страница 52: ...cial applications also called port triggering is typically used for online gaming applications or communication applications that require a range of ports or several ports to be dynamically opened on...

Страница 53: ...tom of the page Note If you would like to discard the changes click Undo before you click Save Prioritize traffic using QoS Quality of Service Configuration Advanced Setting QoS You may want to priori...

Страница 54: ...anges click Save at the bottom of the page Note If you would like to discard the changes click Undo before you click Save Create schedules Configuration Advanced Setting Scheduling For additional secu...

Страница 55: ...e period specified in the schedule and deactivated during the time period not specified Add static routes to your router Configuration Advanced Setting Routing You may want set up your router to route...

Страница 56: ...ers If other routers support dynamic routing such as RIP Routing Information Protocol you can enable this feature on your router to automatically learn the required routes to reach those networks It i...

Страница 57: ...and select one of the following Dynamic IP Address Static IP Address or PPP over Ethernet 4 Next to NAT Disable check the Enable option 5 To save changes click Save at the bottom of the page Note If...

Страница 58: ...of your router Use this method if you are encountering difficulties with accessing your router management page Push and hold this button for 20 seconds and release to reset your router to its factory...

Страница 59: ...eb browser settings you may be prompted to save a file specify the location or the file may be downloaded automatically to the web browser settings default download folder Default Filename config bin...

Страница 60: ...rade process Do not turn off the device or press the Reset button during the upgrade If you are upgrade the firmware using a laptop computer ensure that the laptop is connected to a power source or en...

Страница 61: ...router management page on page 36 2 Click on Configuration at the top of the page click on Toolbox and click on Reboot 3 You will be prompted to reboot your router Click Yes or OK Check connectivity...

Страница 62: ...ng a dynamic IP address Internet connection type this will display the time remaining of your IP address leave from the ISP until your router will request for a new IP address IP Address The current I...

Страница 63: ...e Clicking Refresh at the bottom of the page will refresh the information on the status page Clicking View Log will bring you to log page Configuration Toolbox System Information See the View your rou...

Страница 64: ...llows you to download the current log to your local computer Default Filename system log Clear logs Clears all logging View your router log Configuration Toolbox System Information Your router log can...

Страница 65: ...dically while away from home You may also want to only see specific categories of logging Send router logs to an external log server 1 Log into your router management page see Access your router manag...

Страница 66: ...er 1 Log into your router management page see Access your router management page on page 36 2 Click on Configuration at the top of the page click on Advanced Setting and click on SNMP 3 Review the opt...

Страница 67: ...ion o DMZ Security o Setting Overview o Packet Filters o URL Filters o Keyword Blocking o MAC Control o GRE Tunneling o VPN IPsec o VPN L2TP Client o VPN L2TP Server o VPN PPTP Client o VPN PPTP Serve...

Страница 68: ...tion DPD Local Remote ID FQDN E Mail Key ID PPTP L2TP VPN Protocols Authentication PAP CHAP MS CHAP v1 2 Encryption MPPE 40 56 128 bit Access Control Virtual Servers Packet MAC IP Packet Filters URL K...

Страница 69: ...n b Right click the Local Area Connection icon and the click Properties c Click Internet Protocol TCP IP and click Properties d Then click Obtain an IP address automatically and click OK Note If you a...

Страница 70: ...pport tab Click on Details for more IP address information MAC OS 10 6 10 5 1 From the Apple menu select System Preferences 2 In System Preferences from the View menu select Network 3 In the Network p...

Страница 71: ...button In MAC 10 5 from the Configure drop down list select Using DHCP and click the Apply button In MAC 10 6 from the Configure drop down list select Using DHCP and click the Apply button f Restart y...

Страница 72: ...ch never the same and assign a longer time value to Phase 1 than Phase 2 Assigning the same value may cause VPN connectivity problems between the VPN endpoints Encapsulation Protocol You can choose be...

Страница 73: ...c main configuration page Remote Local ID This provides an additional layer of identification or authentication on the VPN tunnel You can choose Username FQDN User FQDN or Key ID These settings must m...

Страница 74: ...cryption Select the encryption method You can choose between DES 3DES AES 128 AES 192 or AES 256 o DES Data Encryption Standard Weaker encryption strength It uses a symmetric key algorithm with 56 bit...

Страница 75: ...ion allows computer and network devices to communicate using NetBIOS computer or host names instead of IP addresses over the GRE tunnel Additional PPTP L2TP options Authentication Protocol o PAP Passw...

Страница 76: ...Internet address enter the remote router WAN Internet IP address and then click Next 7 Enter the user name and password account information you configured in your router and check Show characters to v...

Страница 77: ...configured in your router and check Show characters to verify and Remember this password to save the credentials Click Connect 8 Your computer will attempt to connect to the PPTP VPN server router 9...

Страница 78: ...ction Wizard window click Finish 10 Enter the user name and password account information you configured in your router and check Save this user name and password for the following users Me only to sav...

Страница 79: ...uld void the user s authority to operate this equipment This device complies with Part 15 of the FCC Rules Operation is subject to the following two conditions 1 This device may not cause harmful inte...

Страница 80: ...E Latviski Latvian Ar o TRENDnet deklar ka TW100 BRV214 atbilst Direkt vas 2004 108 EK b tiskaj m pras b m un citiem ar to saist tajiem noteikumiem Lietuvi Lithuanian iuo TRENDnet deklaruoja kad is TW...

Страница 81: ...y tax and other fees WARRANTIES EXCLUSIVE IF THE TRENDNET PRODUCT DOES NOT OPERATE AS WARRANTED ABOVE THE CUSTOMER S SOLE REMEDY SHALL BE AT TRENDNET S OPTION REPAIR OR REPLACE THE FOREGOING WARRANTIE...

Страница 82: ......

Отзывы: