Chapter 19 VPN
VMG1312-B10C User’s Guide
217
•
Inside header
: The inside IP header contains the destination IP address of the final system
behind the VPN gateway. The security protocol appears after the outer IP header and before the
inside IP header.
19.3.3 IKE Phases
There are two phases to every IKE (Internet Key Exchange) negotiation – phase 1 (Authentication)
and phase 2 (Key Exchange). A phase 1 exchange establishes an IKE SA and the second one uses
that SA to negotiate SAs for IPSec.
Figure 124
Two Phases to Set Up the IPSec SA
In phase 1 you must:
• Choose a negotiation mode.
• Authenticate the connection by entering a pre-shared key.
• Choose an encryption algorithm.
• Choose an authentication algorithm.
• Choose a Diffie-Hellman public-key cryptography key group
.
• Set the IKE SA lifetime. This field allows you to determine how long an IKE SA should stay up
before it times out. An IKE SA times out when the IKE SA lifetime period expires. If an IKE SA
times out when an IPSec SA is already established, the IPSec SA stays connected.
In phase 2 you must:
• Choose an encryption algorithm.
• Choose an authentication algorithm
• Choose a Diffie-Hellman public-key cryptography key group
.
• Set the IPSec SA lifetime. This field allows you to determine how long the IPSec SA should stay
up before it times out. The Device automatically renegotiates the IPSec SA if there is traffic when
the IPSec SA lifetime period expires. If an IPSec SA times out, then the IPSec router must
renegotiate the SA the next time someone attempts to send traffic.
Содержание VMG1312-B10C
Страница 4: ...Contents Overview VMG1312 B10C User s Guide 4 Diagnostic 265 Troubleshooting 271 ...
Страница 14: ...Table of Contents VMG1312 B10C User s Guide 14 ...
Страница 15: ...15 PART I User s Guide ...
Страница 16: ...16 ...
Страница 22: ...Chapter 1 Introducing the Device VMG1312 B10C User s Guide 22 ...
Страница 33: ...33 PART II Technical Reference ...
Страница 34: ...34 ...
Страница 64: ...Chapter 5 Broadband VMG1312 B10C User s Guide 64 ...
Страница 100: ...Chapter 6 Wireless VMG1312 B10C User s Guide 100 ...
Страница 124: ...Chapter 7 Home Networking VMG1312 B10C User s Guide 124 ...
Страница 166: ...Chapter 10 Network Address Translation NAT VMG1312 B10C User s Guide 166 ...
Страница 176: ...Chapter 12 Interface Group VMG1312 B10C User s Guide 176 ...
Страница 192: ...Chapter 14 Firewall VMG1312 B10C User s Guide 192 ...
Страница 198: ...Chapter 16 Parental Control VMG1312 B10C User s Guide 198 ...
Страница 208: ...Chapter 18 Certificates VMG1312 B10C User s Guide 208 ...
Страница 211: ...Chapter 19 VPN VMG1312 B10C User s Guide 211 Figure 121 IPSec VPN Add ...
Страница 224: ...Chapter 20 Log VMG1312 B10C User s Guide 224 ...
Страница 234: ...Chapter 24 IGMP Status VMG1312 B10C User s Guide 234 ...
Страница 238: ...Chapter 25 xDSL Statistics VMG1312 B10C User s Guide 238 ...
Страница 242: ...Chapter 27 User Account VMG1312 B10C User s Guide 242 ...
Страница 248: ...Chapter 30 TR 064 VMG1312 B10C User s Guide 248 ...
Страница 252: ...Chapter 31 Time Settings VMG1312 B10C User s Guide 252 ...
Страница 264: ...Chapter 35 Configuration VMG1312 B10C User s Guide 264 ...
Страница 270: ...Chapter 36 Diagnostic VMG1312 B10C User s Guide 270 ...
Страница 288: ...Appendix B Legal Information VMG1312 B10C User s Guide 288 ...