Chapter 19 VPN
VMG1312-B10C User’s Guide
214
Phase 2
Encryption
Algorithm
Select which key size and encryption algorithm to use in the IKE SA. Choices are:
DES
- a 56-bit key with the DES encryption algorithm
3DES
- a 168-bit key with the DES encryption algorithm
AES128
- a 128-bit key with the AES encryption algorithm
AES196
- a 196-bit key with the AES encryption algorithm
AES256
- a 256-bit key with the AES encryption algorithm
NULL
- no encryption key or algorithm
The Device and the remote IPSec router must use the same key size and encryption
algorithm. Longer keys require more processing power, resulting in increased latency
and decreased throughput.
Integrity
Algorithm
Select which hash algorithm to use to authenticate packet data. Choices are
MD5
,
SHA1
.
SHA
is generally considered stronger than
MD5
, but it is also slower.
Diffie-Hellman
Group for Key
Exchange
Select which Diffie-Hellman key group you want to use for encryption keys. Choices for
number of bits in the random number are: 768, 1024, 2048, 3072, 4096, 6144, 8192.
Key Life Time
Define the length of time before an IPSec SA automatically renegotiates in this field.
A short SA Life Time increases security by forcing the two VPN gateways to update the
encryption and authentication keys. However, every time the VPN tunnel renegotiates,
all users accessing remote resources are temporarily disconnected.
DPD Active
Enable Dead Peer Detection (DPD) Active check box if you want the Device to make sure
the remote IPSec router is there before it transmits data through the IKE SA. The
remote IPSec router must support DPD. If the remote IPSec router does not respond,
the Device shuts down the IKE SA.
Security Protocol - Manual
Key Exchange
Method
Select the key exchange method:
Auto(IKE)
- Select this to use automatic IKE key management VPN connection policy.
Manual
- Select this option to configure a VPN connection policy that uses a manual key
instead of IKE key management. This may be useful if you have problems with IKE key
management.
Note: Only use manual key as a temporary solution, because it is not as secure as a
regular IPSec SA.
Encryption
Algorithm
Select which key size and encryption algorithm to use in the IKE SA. Choices are:
DES
- a 56-bit key with the DES encryption algorithm
3DES
- a 168-bit key with the DES encryption algorithm
AES
- AES encryption algorithm
Encryption Key
This field is applicable when you select an Encryption Algorithm.
Enter the encryption key, which depends on the encryption algorithm.
DES
- type a unique key 16 hexadecimal characters long
3DES
- type a unique key 48 hexadecimal characters long
AES
- type a unique key 32, 48 or 64 hexadecimal characters long
Authentication
Algorithm
Select which hash algorithm to use to authenticate packet data. Choices are
MD5
,
SHA1
.
SHA
is generally considered stronger than
MD5
, but it is also slower.
Table 92
IPSec VPN: Add
LABEL
DESCRIPTION
Содержание VMG1312-B10C
Страница 4: ...Contents Overview VMG1312 B10C User s Guide 4 Diagnostic 265 Troubleshooting 271 ...
Страница 14: ...Table of Contents VMG1312 B10C User s Guide 14 ...
Страница 15: ...15 PART I User s Guide ...
Страница 16: ...16 ...
Страница 22: ...Chapter 1 Introducing the Device VMG1312 B10C User s Guide 22 ...
Страница 33: ...33 PART II Technical Reference ...
Страница 34: ...34 ...
Страница 64: ...Chapter 5 Broadband VMG1312 B10C User s Guide 64 ...
Страница 100: ...Chapter 6 Wireless VMG1312 B10C User s Guide 100 ...
Страница 124: ...Chapter 7 Home Networking VMG1312 B10C User s Guide 124 ...
Страница 166: ...Chapter 10 Network Address Translation NAT VMG1312 B10C User s Guide 166 ...
Страница 176: ...Chapter 12 Interface Group VMG1312 B10C User s Guide 176 ...
Страница 192: ...Chapter 14 Firewall VMG1312 B10C User s Guide 192 ...
Страница 198: ...Chapter 16 Parental Control VMG1312 B10C User s Guide 198 ...
Страница 208: ...Chapter 18 Certificates VMG1312 B10C User s Guide 208 ...
Страница 211: ...Chapter 19 VPN VMG1312 B10C User s Guide 211 Figure 121 IPSec VPN Add ...
Страница 224: ...Chapter 20 Log VMG1312 B10C User s Guide 224 ...
Страница 234: ...Chapter 24 IGMP Status VMG1312 B10C User s Guide 234 ...
Страница 238: ...Chapter 25 xDSL Statistics VMG1312 B10C User s Guide 238 ...
Страница 242: ...Chapter 27 User Account VMG1312 B10C User s Guide 242 ...
Страница 248: ...Chapter 30 TR 064 VMG1312 B10C User s Guide 248 ...
Страница 252: ...Chapter 31 Time Settings VMG1312 B10C User s Guide 252 ...
Страница 264: ...Chapter 35 Configuration VMG1312 B10C User s Guide 264 ...
Страница 270: ...Chapter 36 Diagnostic VMG1312 B10C User s Guide 270 ...
Страница 288: ...Appendix B Legal Information VMG1312 B10C User s Guide 288 ...