ADSL2/2+ 11N WiFi Router User’s Manual
38
Pre-Shared Key
Specify the Key if you select the authentication method as
Pre-Shared Key.
Certificate
Select the certificate from drop-down list if you select the
authentication method as Certificate X.509.
Perfect Forward Secrecy
Select to enable or disable Perfect Forward Secrecy (PFS)
feature.
Encryption Algorithm
Select the encryption algorithm to be DES, 3DES or AES
(aec-cbc).
Encryption Key
Enter the encryption key to be 3DES or AES (Advanced
Encryption Standard).
Authentication Algorithm
Select the authentication algorithm from drop-down list.
Authentication Key
Enter the authentication key to be MD5 or SHA1.
SPI
Enter the SPI (Security Parameter Index) which is an
identification tag added to the header tunneling the IP traffic.
There are two phases of IPSec:
Phase 1
: Start to negotiate IKE parameters including encryption, integrity (hash), Diffie-
Hellman parameter values and lifetime to protect the following IKE exchange. The peer that
starts the negotiation proposes all its policies to the remote peer and then remote peer tries to
find a highest-priority to match with its policies. This sets up a secure tunnel for IKE Phase 2.
Phase 2
: Start to negotiate IPSec security for the following IKE exchange and mutual
examination of the secure tunnel establishment.
Note
It is critical that the exact same Phase 1 and Phase 2 proposals be entered at
the remote client.
Field Description
Advanced IKE Settings
This button is available when you select the
Key Exchange
Method
as Auto mode.
Mode
Select the mode to be Main or Aggressive.
Encryption Algorithm
Select the encryption algorithm to be DES, 3DES, AES-128,
AES-196 or AES-256.
Integrity Algorithm
Select the integrity algorithm to be MD5 or SHA1.
Select Diffie-Hellman
Group for Key Exchange
Select the Diffie-Hellman group to be 768, 1024, 1536,
2048, 3072, 4096, 6144 or 8192-bit for key exchange.
Key Life Time
Configure the life time for Key (in second).
6.18 Certificate
This section allows you to create certificates.
6.18.1 Local
This page allows you to crate local certificate. Local certificates are used by peers to verify
your identity. You can either create certificate request or import the certificate to add local
certificates. Maximum 4 certificates can be stored.