14.1.2.11.1 Connection with Server
279
Preshared key
Using this setting, the peer will be authenticated by a preshared key. To enhance
the security of the connection the preshared key should be a rather complicated
passphrase instead of a simple password. Use lowercase and uppercase letters,
digits and special characters and avoid words that can be found in a dictionary.
For all peers with a dynamic IP the same preshared key
has to be used. Therefore it is configured along with the
settings of the ipsec interface and not with the connection
specific settings.
Local ID
With preshared key authentication the external IP addresses are used by the peers
to mutually identify each other. If necessary, a different IP can be specified. Also
hostnames or email addresses can be used instead of IPs.
Here you can modify the ID SX-GATE sends to the peer.
Remote ID (with PSK)
If a peer with static IP has been configured, its external IP is expected as ID. In case the
peer uses a different IP (e.g. because it is situated behind a NAT router), a hostname
(FQDN) or an email address (USER@FQDN) as its ID, you must supply it here.
For a peer with dynamic IP it makes sense to configure a static ID on the peer and
configure this ID here. This reduces the risk that the wrong party connects with this
server connection in case that multiple peers use the same preshared key.
Preshared key
If authentication by preshared key has been selected, you have to supply the key
here. To offer the expected security of a VPN connection, the preshared key should
be a rather complicated passphrase instead of a simple password. Use lowercase and
uppercase letters, digits and special characters and avoid words that can be found
in a dictionary. If these conditions are met, the recommended minimum length of the
preshared key depending on cipher and hash algorithm are:
Encryption
Hash
Characters
3DES
MD5 / SHA1
14
AES-128
SHA2-256
22
AES-256
SHA2-512
43
Содержание SX-GATE
Страница 1: ...State 2016 12 13 V7 0 2 0 User Guide ...
Страница 92: ...12 1 Setup 92 There s no way to restore a purchased certificate without backup ...
Страница 126: ...12 3 3 Groups 126 12 3 3 C Usage This table show in which settings the definition is used ...
Страница 476: ...15 3 Apple iPhone 476 ...