P-662H/HW-D Series User’s Guide
Chapter 16 VPN Screens
257
16.14 Manual Key Setup
Manual key management is useful if you have problems with
IKE
key management.
16.14.1 Security Parameter Index (SPI)
An SPI is used to distinguish different SAs terminating at the same destination and using the
same IPSec protocol. This data allows for the multiplexing of SAs to a single gateway. The
SPI
(Security Parameter Index) along with a destination IP address uniquely identify a
particular Security Association (SA). The
SPI
is transmitted from the remote VPN gateway to
the local VPN gateway. The local VPN gateway then uses the network, encryption and key
values that the administrator associated with the SPI to establish the tunnel.
Current ZyXEL implementation assumes identical outgoing and incoming SPIs.
16.15 Configuring Manual Key
You only configure
VPN Manual Key
when you select
Manual
in the
IPSec Key Mode
field
on the
VPN IKE
screen. This is the
VPN Manual Key
screen as shown next.
Authentication
Algorithm
Select
SHA1
or
MD5
from the drop-down list box. MD5 (Message Digest 5) and
SHA1 (Secure Hash Algorithm) are hash algorithms used to authenticate packet
data. The SHA1 algorithm is generally considered stronger than MD5, but is
slower. Select
MD5
for minimal security and
SHA-1
for maximum security.
SA Life Time
(Seconds)
Define the length of time before an IKE SA automatically renegotiates in this field.
It may range from 60 to 3,000,000 seconds (almost 35 days).
A short SA Life Time increases security by forcing the two VPN gateways to
update the encryption and authentication keys. However, every time the VPN
tunnel renegotiates, all users accessing remote resources are temporarily
disconnected.
Encapsulation Select
Tunnel
mode or
Transport
mode from the drop-down list box.
Perfect Forward
Secrecy (PFS)
Perfect Forward Secrecy (PFS) is disabled (
NONE
) by default in phase 2 IPSec
SA setup. This allows faster IPSec setup, but is not so secure. Choose
DH1
or
DH2
from the drop-down list box to enable PFS.
DH1
refers to Diffie-Hellman
Group 1 a 768 bit random number.
DH2
refers to Diffie-Hellman Group 2 a 1024
bit (1Kb) random number (more secure, yet slower).
Apply
Click
Apply
to save your changes back to the ZyXEL Device and return to the
VPN-IKE
screen.
Cancel
Click
Cancel
to return to the
VPN-IKE
screen without saving your changes.
Table 95
Advanced VPN Policies
LABEL
DESCRIPTION
Содержание 802.11g ADSL 2+ 4-Port Security Gateway HW-D Series
Страница 1: ...P 662H HW D Series 802 11g ADSL 2 4 Port Security Gateway User s Guide Version 3 40 Edition 1 7 2006 ...
Страница 2: ......
Страница 10: ...P 662H HW D Series User s Guide 10 Customer Support ...
Страница 24: ...P 662H HW D Series User s Guide 24 Table of Contents ...
Страница 32: ...P 662H HW D Series User s Guide 32 List of Figures ...
Страница 38: ...P 662H HW D Series User s Guide 38 List of Tables ...
Страница 64: ...P 662H HW D Series User s Guide 64 Chapter 2 Introducing the Web Configurator ...
Страница 84: ...P 662H HW D Series User s Guide 84 Chapter 4 Bandwidth Management Wizard ...
Страница 108: ...P 662H HW D Series User s Guide 108 Chapter 5 WAN Setup ...
Страница 122: ...P 662H HW D Series User s Guide 122 Chapter 6 LAN Setup ...
Страница 155: ...P 662H HW D Series User s Guide Chapter 8 DMZ 155 Figure 81 DMZ Private and Public Address Example ...
Страница 156: ...P 662H HW D Series User s Guide 156 Chapter 8 DMZ ...
Страница 188: ...P 662H HW D Series User s Guide 188 Chapter 11 Firewall Configuration Figure 97 Firewall Edit Rule ...
Страница 202: ...P 662H HW D Series User s Guide 202 Chapter 11 Firewall Configuration ...
Страница 210: ...P 662H HW D Series User s Guide 210 Chapter 12 Anti Virus Packet Scan ...
Страница 214: ...P 662H HW D Series User s Guide 214 Chapter 13 Content Filtering ...
Страница 232: ...P 662H HW D Series User s Guide 232 Chapter 14 Content Access Control ...
Страница 238: ...P 662H HW D Series User s Guide 238 Chapter 15 Introduction to IPSec ...
Страница 273: ...P 662H HW D Series User s Guide Chapter 17 Certificates 273 Figure 144 My Certificate Details ...
Страница 284: ...P 662H HW D Series User s Guide 284 Chapter 17 Certificates Figure 152 Trusted Remote Host Details ...
Страница 292: ...P 662H HW D Series User s Guide 292 Chapter 18 Static Route ...
Страница 303: ...P 662H HW D Series User s Guide Chapter 19 Bandwidth Management 303 Figure 162 Bandwidth Management Monitor ...
Страница 304: ...P 662H HW D Series User s Guide 304 Chapter 19 Bandwidth Management ...
Страница 308: ...P 662H HW D Series User s Guide 308 Chapter 20 Dynamic DNS Setup ...
Страница 332: ...P 662H HW D Series User s Guide 332 Chapter 22 Universal Plug and Play UPnP ...
Страница 338: ...P 662H HW D Series User s Guide 338 Chapter 23 System ...
Страница 344: ...P 662H HW D Series User s Guide 344 Chapter 24 Logs ...
Страница 350: ...P 662H HW D Series User s Guide 350 Chapter 25 Tools ...
Страница 363: ...P 662H HW D Series User s Guide Chapter 27 Troubleshooting 363 Figure 213 Security Setting ActiveX Controls ...
Страница 364: ...P 662H HW D Series User s Guide 364 Chapter 27 Troubleshooting ...
Страница 368: ...P 662H HW D Series User s Guide 368 Product Specifications ...
Страница 372: ...P 662H HW D Series User s Guide 372 Appendix C Wall mounting Instructions ...
Страница 408: ...P 662H HW D Series User s Guide 408 Appendix F Wireless LANs ...
Страница 420: ...P 662H HW D Series User s Guide 420 Appendix H Command Interpreter ...
Страница 436: ...P 662H HW D Series User s Guide 436 Appendix L NetBIOS Filter Commands ...
Страница 462: ...P 662H HW D Series User s Guide 462 Appendix M Internal SPTGEN ...
Страница 484: ...P 662H HW D Series User s Guide 484 Appendix P Triangle Route ...