Manual VPN: Setting Up Manual VPN Tunnels
204
Firebox X Edge e-Series
ID. The remote device must identify your Firebox X Edge by domain name, and it must use the
same public IP address as the domain name in its Phase 1 setup.
Phase 2 settings
Phase 2 negotiates the data management security association for the tunnel. The tunnel uses this
phase to create IPSec tunnels and put data packets together.
You can use the default Phase 2 settings to make configuration easier.
Make sure that the Phase 2 configuration is the same on the two devices.
To change the Phase 2 settings:
1
Select the authentication method from the
Authentication Algorithm
drop-down list.
2
Select the encryption algorithm from the
Encryption Algorithm
drop-down list.
3
TOS bits are a set of four-bit flags in the IP header that can tell routing devices to give some VPN
traffic higher priority. Some ISPs drop all packets that have TOS flags set. If you select the
Enable
TOS for IPSec
check box, the Edge preserves existing TOS bits in VPN traffic packets. If the check
box is not selected, the Edge removes TOS bits.
4
To use Perfect Forward Secrecy, select the
Enable Perfect Forward Secrecy
check box.
This option makes sure that each new key comes from a new Diffie-Hellman exchange. This
option makes the negotiation more secure, but uses more time and computer resources.
5
Type the number of kilobytes and the number of hours until the Phase 2 key expires.
To make the key not expire, enter zero (0). For example, 24 hours and zero (0) kilobytes means
that the Phase 2 key is renegotiated each 24 hours no matter how much data has passed.
6
Type the IP address of the local network and the remote networks that will send encrypted traffic
across the VPN.
You must enter network addresses in “slash” notation (also known as CIDR or Classless Inter
Domain Routing notation). For more information on how to enter IP addresses in slash notation,
Содержание Firebox X20E
Страница 20: ...The Firebox X Edge and Your Network 8 Firebox X Edge e Series...
Страница 32: ...Using the Quick Setup Wizard 20 Firebox X Edge e Series...
Страница 64: ...Viewing the Configuration File 52 Firebox X Edge e Series...
Страница 92: ...Configuring BIDS 80 Firebox X Edge e Series...
Страница 102: ...Configuring the Wireless Card on Your Computer 90 Firebox X Edge e Series...
Страница 114: ...Configuring Policies for the Optional Network 102 Firebox X Edge e Series...
Страница 138: ...Using Additional Services for Proxies 126 Firebox X Edge e Series...
Страница 158: ...Working with Firewall NAT 146 Firebox X Edge e Series...
Страница 166: ...Using Certificates on the Firebox X Edge 154 Firebox X Edge e Series...
Страница 208: ...Updating Gateway AV IPS 196 Firebox X Edge e Series...
Страница 220: ...Frequently Asked Questions 208 Firebox X Edge e Series...
Страница 302: ...Limited Hardware Warranty 290 Firebox X Edge e Series...
Страница 310: ...298 Firebox X Edge e Series...