P-662H/HW-D Series User’s Guide
Chapter 16 VPN Screens
253
• Authenticate the connection by entering a pre-shared key.
• Choose an encryption algorithm.
• Choose an authentication algorithm.
• Choose a Diffie-Hellman public-key cryptography key group (
DH1
or
DH2
)
.
• Set the IKE SA lifetime. This field allows you to determine how long an IKE SA should
stay up before it times out. An IKE SA times out when the IKE SA lifetime period
expires. If an IKE SA times out when an IPSec SA is already established, the IPSec SA
stays connected.
In phase 2 you must:
• Choose which protocol to use (
ESP
or
AH
) for the IKE key exchange.
• Choose an encryption algorithm.
• Choose an authentication algorithm
• Choose whether to enable Perfect Forward Secrecy (PFS) using Diffie-Hellman public-
key cryptography – see
None
(the default) to disable
PFS.
• Choose
Tunnel
mode or
Transport
mode.
• Set the IPSec SA lifetime. This field allows you to determine how long the IPSec SA
should stay up before it times out. The ZyXEL Device automatically renegotiates the
IPSec SA if there is traffic when the IPSec SA lifetime period expires. The ZyXEL
Device also automatically renegotiates the IPSec SA if both IPSec routers have keep alive
enabled, even if there is no traffic. If an IPSec SA times out, then the IPSec router must
renegotiate the SA the next time someone attempts to send traffic.
16.12.1 Negotiation Mode
The phase 1
Negotiation Mode
you select determines how the Security Association (SA) will
be established for each connection through IKE negotiations.
•
Main Mode
ensures the highest level of security when the communicating parties are
negotiating authentication (phase 1). It uses 6 messages in three round trips: SA
negotiation, Diffie-Hellman exchange and an exchange of nonces (a nonce is a random
number). This mode features identity protection (your identity is not revealed in the
negotiation).
•
Aggressive Mode
is quicker than
Main Mode
because it eliminates several steps when
the communicating parties are negotiating authentication (phase 1). However the trade-
off is that faster speed limits its negotiating power and it also does not provide identity
protection. It is useful in remote access situations where the address of the initiator is not
know by the responder and both parties want to use pre-shared key authentication.
Содержание 802.11g ADSL 2+ 4-Port Security Gateway HW-D Series
Страница 1: ...P 662H HW D Series 802 11g ADSL 2 4 Port Security Gateway User s Guide Version 3 40 Edition 1 7 2006 ...
Страница 2: ......
Страница 10: ...P 662H HW D Series User s Guide 10 Customer Support ...
Страница 24: ...P 662H HW D Series User s Guide 24 Table of Contents ...
Страница 32: ...P 662H HW D Series User s Guide 32 List of Figures ...
Страница 38: ...P 662H HW D Series User s Guide 38 List of Tables ...
Страница 64: ...P 662H HW D Series User s Guide 64 Chapter 2 Introducing the Web Configurator ...
Страница 84: ...P 662H HW D Series User s Guide 84 Chapter 4 Bandwidth Management Wizard ...
Страница 108: ...P 662H HW D Series User s Guide 108 Chapter 5 WAN Setup ...
Страница 122: ...P 662H HW D Series User s Guide 122 Chapter 6 LAN Setup ...
Страница 155: ...P 662H HW D Series User s Guide Chapter 8 DMZ 155 Figure 81 DMZ Private and Public Address Example ...
Страница 156: ...P 662H HW D Series User s Guide 156 Chapter 8 DMZ ...
Страница 188: ...P 662H HW D Series User s Guide 188 Chapter 11 Firewall Configuration Figure 97 Firewall Edit Rule ...
Страница 202: ...P 662H HW D Series User s Guide 202 Chapter 11 Firewall Configuration ...
Страница 210: ...P 662H HW D Series User s Guide 210 Chapter 12 Anti Virus Packet Scan ...
Страница 214: ...P 662H HW D Series User s Guide 214 Chapter 13 Content Filtering ...
Страница 232: ...P 662H HW D Series User s Guide 232 Chapter 14 Content Access Control ...
Страница 238: ...P 662H HW D Series User s Guide 238 Chapter 15 Introduction to IPSec ...
Страница 273: ...P 662H HW D Series User s Guide Chapter 17 Certificates 273 Figure 144 My Certificate Details ...
Страница 284: ...P 662H HW D Series User s Guide 284 Chapter 17 Certificates Figure 152 Trusted Remote Host Details ...
Страница 292: ...P 662H HW D Series User s Guide 292 Chapter 18 Static Route ...
Страница 303: ...P 662H HW D Series User s Guide Chapter 19 Bandwidth Management 303 Figure 162 Bandwidth Management Monitor ...
Страница 304: ...P 662H HW D Series User s Guide 304 Chapter 19 Bandwidth Management ...
Страница 308: ...P 662H HW D Series User s Guide 308 Chapter 20 Dynamic DNS Setup ...
Страница 332: ...P 662H HW D Series User s Guide 332 Chapter 22 Universal Plug and Play UPnP ...
Страница 338: ...P 662H HW D Series User s Guide 338 Chapter 23 System ...
Страница 344: ...P 662H HW D Series User s Guide 344 Chapter 24 Logs ...
Страница 350: ...P 662H HW D Series User s Guide 350 Chapter 25 Tools ...
Страница 363: ...P 662H HW D Series User s Guide Chapter 27 Troubleshooting 363 Figure 213 Security Setting ActiveX Controls ...
Страница 364: ...P 662H HW D Series User s Guide 364 Chapter 27 Troubleshooting ...
Страница 368: ...P 662H HW D Series User s Guide 368 Product Specifications ...
Страница 372: ...P 662H HW D Series User s Guide 372 Appendix C Wall mounting Instructions ...
Страница 408: ...P 662H HW D Series User s Guide 408 Appendix F Wireless LANs ...
Страница 420: ...P 662H HW D Series User s Guide 420 Appendix H Command Interpreter ...
Страница 436: ...P 662H HW D Series User s Guide 436 Appendix L NetBIOS Filter Commands ...
Страница 462: ...P 662H HW D Series User s Guide 462 Appendix M Internal SPTGEN ...
Страница 484: ...P 662H HW D Series User s Guide 484 Appendix P Triangle Route ...