
Prestige 652 Series User’s Guide
VPN Screens
17-5
Table 17-2 VPN Summary
LABEL
DESCRIPTION
Secure Gateway
IP
This is the IP address of the remote IPSec router. This must be a fixed, public IP address
for traffic going through the Internet.
Back
Click
Back
to return to the previous screen.
17.6 Keep Alive
When you initiate an IPSec tunnel with keep alive enabled, the Prestige automatically renegotiates the tunnel
when the IPSec SA lifetime period expires (see
section 17.10
for more on the IPSec SA lifetime). In effect,
the IPSec tunnel becomes an “always on” connection after you initiate it. Both IPSec routers must have a
Prestige-compatible keep alive feature enabled in order for this feature to work.
If the Prestige has its maximum number of simultaneous IPSec tunnels connected to it and they all have keep
alive enabled, then no other tunnels can take a turn connecting to the Prestige because the Prestige never
drops the tunnels that are already connected. Check
Table 1-1 Model Specific Features
in chapter 1 to see
how many simultaneous IPSec SAs your Prestige model can support.
When there is outbound traffic with no inbound traffic, the Prestige automatically
drops the tunnel after two minutes.
17.7 ID Type and Content
With aggressive negotiation mode (see
section
), the Prestige identifies incoming SAs by ID type and
content since this identifying information is not encrypted. This enables the Prestige to distinguish between
multiple rules for SAs that connect from remote IPSec routers that have dynamic WAN IP addresses.
Telecommuters can use separate passwords to simultaneously connect to the Prestige from IPSec routers with
dynamic IP addresses (see
section 17.16.2
for a telecommuter configuration example).
With main mode (see
section
), the ID type and content are encrypted to provide identity protection.
In this case the Prestige can only distinguish between up to eight different incoming SAs that connect from
remote IPSec routers that have dynamic WAN IP addresses. The Prestige can distinguish up to eight
incoming SAs because you can select between two encryption algorithms (DES and 3DES), two
authentication algorithms (MD5 and SHA1) and two key groups (DH1 and DH2) when you configure a VPN
rule (see
section 17.11
). The ID type and content act as an extra level of identification for incoming SAs.
The type of ID can be a domain name, an IP address or an e-mail address. The content is the IP address,
domain name, or e-mail address.
Содержание Prestige 652 Series
Страница 1: ...Prestige 652 Series ADSL Security Wireless LAN Router User s Guide Version 3 40 June 2003...
Страница 30: ......
Страница 40: ...Prestige 652 Series User s Guide 1 10 Getting To Know Your Prestige Figure 1 4 Prestige LAN to LAN Application...
Страница 60: ......
Страница 62: ......
Страница 86: ......
Страница 99: ...Prestige 652 Series User s Guide WAN Setup 7 13 Figure 7 7 Advanced WAN Backup...
Страница 106: ......
Страница 108: ......
Страница 128: ......
Страница 130: ......
Страница 144: ......
Страница 150: ......
Страница 176: ......
Страница 177: ...VPN IPSec V Part V VPN IPSec This part provides information about configuring VPN IPSec for secure communications...
Страница 178: ......
Страница 192: ...Prestige 652 Series User s Guide 17 8 VPN Screens Figure 17 3 VPN IKE...
Страница 212: ......
Страница 214: ......
Страница 233: ...Maintenance VII Part VII Maintenance This part covers the maintenance screens...
Страница 234: ......
Страница 248: ......
Страница 250: ......
Страница 260: ......
Страница 276: ......
Страница 292: ......
Страница 334: ......
Страница 374: ......
Страница 396: ......
Страница 400: ......
Страница 410: ......
Страница 416: ......
Страница 432: ......
Страница 440: ......
Страница 446: ......
Страница 457: ...Prestige 652 Series User s Guide Wireless LAN and IEEE 802 11 C 3 Diagram C 2 ESS Provides Campus Wide Coverage...
Страница 458: ......
Страница 462: ......
Страница 502: ......
Страница 516: ......