Prestige 792H User’s Guide
14-18
VPN
Screens
Table 14-8 VPN IKE: Advanced
LABEL
DESCRIPTION
Encryption
Algorithm
Select
DES
,
3DES
or
NULL
from the drop-down list box.
When DES is used for data communications, both sender and receiver must know
the same secret key, which can be used to encrypt and decrypt the message or to
generate and verify a message authentication code. The DES encryption algorithm
uses a 56-bit key. Triple DES (
3DES
) is a variation on DES that uses a 168-bit key.
As a result, 3DES is more secure than DES. It also requires more processing power,
resulting in increased latency and decreased throughput. Select NULL to set up a
tunnel without encryption. When you select NULL, you do not enter an encryption
key.
Authentication
Algorithm
Select
SHA1
or
MD5
from the drop-down list box. MD5 (Message Digest 5) and
SHA1 (Secure Hash Algorithm) are hash algorithms used to authenticate packet
data. The SHA1 algorithm is generally considered stronger than MD5, but is slower.
Select
MD5
for minimal security and
SHA-1
for maximum security.
SA Life Time
(Seconds)
Define the length of time before an IKE SA automatically renegotiates in this field. It
may range from 60 to 3,000,000 seconds (almost 35 days).
A short SA Life Time increases security by forcing the two VPN gateways to update
the encryption and authentication keys. However, every time the VPN tunnel
renegotiates, all users accessing remote resources are temporarily disconnected.
Encapsulation
Select
Tunnel
mode or
Transport
mode from the drop-down list box.
Perfect Forward
Secrecy (PFS)
Perfect Forward Secrecy (PFS) is disabled (
None
) by default in phase 2 IPSec SA
setup. This allows faster IPSec setup, but is not so secure. Choose
DH1
or
DH2
from
the drop-down list box to enable PFS.
DH1
refers to Diffie-Hellman Group 1 a 768 bit
random number.
DH2
refers to Diffie-Hellman Group 2 a 1024 bit (1Kb) random
number (more secure, yet slower).
Apply
Click
Apply
to save your changes back to the Prestige and return to the
VPN IKE
screen.
Cancel
Click
Cancel
to return to the
VPN IKE
screen without saving your changes.
14.12 Manual Key Setup
Manual key management is useful if you have problems with
IKE
key management.
Содержание Prestige 792H
Страница 1: ...Prestige 792H G SHDSL 4 port Security Gateway User s Guide Version 3 40 BZ 0 March 2004...
Страница 8: ......
Страница 32: ......
Страница 34: ......
Страница 40: ......
Страница 46: ......
Страница 66: ......
Страница 86: ...Prestige 792H User s Guide 5 14 WAN Setup Figure 5 6 Advanced WAN Backup...
Страница 94: ......
Страница 108: ......
Страница 112: ......
Страница 134: ......
Страница 163: ...VPN IPSec IV Part IV VPN IPSec This part provides information about configuring VPN IPSec for secure communications...
Страница 164: ......
Страница 178: ...Prestige 792H User s Guide 14 8 VPN Screens Figure 14 3 VPN IKE...
Страница 205: ...Remote Management and UPnP V Part V Remote Management and UPnP This part contains Remote Management and UPnP...
Страница 206: ......
Страница 210: ......
Страница 220: ......
Страница 221: ...Maintenance VI Part VI Maintenance This part covers the maintenance screens...
Страница 222: ......
Страница 234: ......
Страница 236: ......
Страница 246: ......
Страница 268: ......
Страница 270: ......
Страница 282: ......
Страница 286: ......
Страница 312: ......
Страница 334: ......
Страница 348: ......
Страница 370: ......
Страница 380: ......
Страница 388: ......
Страница 390: ......
Страница 406: ......
Страница 410: ......
Страница 415: ...XI Part XI Appendices and Index This section provides some Appendices and an Index...
Страница 416: ......
Страница 420: ......
Страница 424: ......
Страница 426: ......
Страница 430: ......