Prestige 661H/HW Series User’s Guide
189
Chapter 15 VPN Screens
In phase 2 you must:
• Choose which protocol to use (
ESP
or
AH
) for the IKE key exchange.
• Choose an encryption algorithm.
• Choose an authentication algorithm
• Choose whether to enable Perfect Forward Secrecy (PFS) using Diffie-Hellman public-
key cryptography – see
. Select
None
(the default) to disable
PFS.
• Choose
Tunnel
mode or
Transport
mode.
• Set the IPSec SA lifetime. This field allows you to determine how long the IPSec SA
should stay up before it times out. The Prestige automatically renegotiates the IPSec SA
if there is traffic when the IPSec SA lifetime period expires. The Prestige also
automatically renegotiates the IPSec SA if both IPSec routers have keep alive enabled,
even if there is no traffic. If an IPSec SA times out, then the IPSec router must renegotiate
the SA the next time someone attempts to send traffic.
15.11.1 Negotiation Mode
The phase 1
Negotiation Mode
you select determines how the Security Association (SA) will
be established for each connection through IKE negotiations.
•
Main Mode
ensures the highest level of security when the communicating parties are
negotiating authentication (phase 1). It uses 6 messages in three round trips: SA
negotiation, Diffie-Hellman exchange and an exchange of nonces (a nonce is a random
number). This mode features identity protection (your identity is not revealed in the
negotiation).
•
Aggressive Mode
is quicker than
Main Mode
because it eliminates several steps when
the communicating parties are negotiating authentication (phase 1). However the trade-
off is that faster speed limits its negotiating power and it also does not provide identity
protection. It is useful in remote access situations where the address of the initiator is not
know by the responder and both parties want to use pre-shared key authentication.
15.11.2 Diffie-Hellman (DH) Key Groups
Diffie-Hellman (DH) is a public-key cryptography protocol that allows two parties to establish
a shared secret over an unsecured communications channel. Diffie-Hellman is used within
IKE SA setup to establish session keys. 768-bit (Group 1 -
DH1
) and 1024-bit (Group 2 –
DH2
) Diffie-Hellman groups are supported. Upon completion of the Diffie-Hellman
exchange, the two peers have a shared secret, but the IKE SA is not authenticated. For
authentication, use pre-shared keys.
Содержание Prestige 661H Series
Страница 37: ...Prestige 661H HW Series User s Guide 37 List of Tables...
Страница 41: ...Prestige 661H HW Series User s Guide 41 Introduction to DSL...
Страница 51: ...Prestige 661H HW Series User s Guide 51 Chapter 1 Getting To Know Your Prestige...
Страница 67: ...Prestige 661H HW Series User s Guide 67 Chapter 3 Wizard Setup for Internet Access...
Страница 81: ...Prestige 661H HW Series User s Guide 81 Chapter 5 LAN Setup...
Страница 125: ...Prestige 661H HW Series User s Guide 125 Chapter 8 Network Address Translation NAT Screens...
Страница 143: ...Prestige 661H HW Series User s Guide 143 Chapter 11 Firewalls...
Страница 151: ...Prestige 661H HW Series User s Guide 151 Chapter 12 Firewall Configuration Figure 64 Firewall Edit Rule...
Страница 165: ...Prestige 661H HW Series User s Guide 165 Chapter 12 Firewall Configuration...
Страница 169: ...Prestige 661H HW Series User s Guide 169 Chapter 13 Content Filtering...
Страница 175: ...Prestige 661H HW Series User s Guide 175 Chapter 14 Introduction to IPSec...
Страница 203: ...Prestige 661H HW Series User s Guide 203 Chapter 15 VPN Screens...
Страница 207: ...Prestige 661H HW Series User s Guide 207 Chapter 16 Remote Management Configuration...
Страница 221: ...Prestige 661H HW Series User s Guide 221 Chapter 17 Universal Plug and Play UPnP...
Страница 227: ...Prestige 661H HW Series User s Guide 227 Chapter 18 Logs Screens...
Страница 241: ...Prestige 661H HW Series User s Guide 241 Chapter 19 Media Bandwidth Management Advanced Setup...
Страница 265: ...Prestige 661H HW Series User s Guide 265 Chapter 21 Maintenance...
Страница 275: ...Prestige 661H HW Series User s Guide 275 Chapter 23 Menu 1 General Setup...
Страница 279: ...Prestige 661H HW Series User s Guide 279 Chapter 24 Menu 2 WAN Backup Setup...
Страница 283: ...Prestige 661H HW Series User s Guide 283 Chapter 25 Menu 3 LAN Setup...
Страница 287: ...Prestige 661H HW Series User s Guide 287 Chapter 26 Wireless LAN Setup...
Страница 293: ...Prestige 661H HW Series User s Guide 293 Chapter 27 Internet Access...
Страница 307: ...Prestige 661H HW Series User s Guide 307 Chapter 29 Static Route Setup...
Страница 311: ...Prestige 661H HW Series User s Guide 311 Chapter 30 Bridging Setup...
Страница 327: ...Prestige 661H HW Series User s Guide 327 Chapter 31 Network Address Translation NAT...
Страница 343: ...Prestige 661H HW Series User s Guide 343 Chapter 33 Filter Configuration...
Страница 363: ...Prestige 661H HW Series User s Guide 363 Chapter 36 System Information and Diagnosis...
Страница 375: ...Prestige 661H HW Series User s Guide 375 Chapter 37 Firmware and Configuration File Maintenance...
Страница 381: ...Prestige 661H HW Series User s Guide 381 Chapter 38 System Maintenance...
Страница 385: ...Prestige 661H HW Series User s Guide 385 Chapter 39 Remote Management...
Страница 395: ...Prestige 661H HW Series User s Guide 395 Chapter 40 IP Policy Routing...
Страница 399: ...Prestige 661H HW Series User s Guide 399 Chapter 41 Call Scheduling...
Страница 411: ...Prestige 661H HW Series User s Guide 411 Chapter 42 VPN IPSec Setup...
Страница 415: ...Prestige 661H HW Series User s Guide 415 Chapter 43 SA Monitor...
Страница 427: ...Prestige 661H HW Series User s Guide 427 Chapter 44 Troubleshooting Figure 275 Security Setting ActiveX Controls...
Страница 431: ...Prestige 661H HW Series User s Guide 431 Appendix A...
Страница 451: ...Prestige 661H HW Series User s Guide 451 Appendix C IP Subnetting...
Страница 455: ...Prestige 661H HW Series User s Guide 455 Appendix E Command Interpreter...
Страница 461: ...Prestige 661H HW Series User s Guide 461 Appendix F Firewall Commands...
Страница 464: ...Prestige 661H HW Series User s Guide Appendix G NetBIOS Filter Commands 464...
Страница 465: ...Prestige 661H HW Series User s Guide 465 Appendix G NetBIOS Filter Commands...
Страница 478: ...Prestige 661H HW Series User s Guide Appendix H VPN Setup 478 ftp 5631148 bytes sent in 614 8Seconds 9 17Kbytes sec...
Страница 479: ...Prestige 661H HW Series User s Guide 479 Appendix H VPN Setup...
Страница 482: ...Prestige 661H HW Series User s Guide Appendix I Splitters and Microfilters 482...
Страница 483: ...Prestige 661H HW Series User s Guide 483 Appendix I Splitters and Microfilters...
Страница 537: ...Prestige 661H HW Series User s Guide 537 Appendix M Internal SPTGEN...