Chapter 21 IPSec
VSG1435-B101 Series User’s Guide
257
21.3.1.2 Manual Key Setup
Manual key management is useful if you have problems with
Auto(IKE)
key
management.
21.3.1.3 Security Parameter Index (SPI)
An SPI is used to distinguish different SAs terminating at the same destination and
using the same IPSec protocol. This data allows for the multiplexing of SAs to a
single gateway. The
SPI
(Security Parameter Index) along with a destination IP
address uniquely identify a particular Security Association (SA). The
SPI
is
transmitted from the remote VPN gateway to the local VPN gateway. The local VPN
gateway then uses the network, encryption and key values that the administrator
associated with the SPI to establish the tunnel.
Encryption
Algorithm
Select
DES
,
3DES
,
AES-128
,
ES-192
or
AES-256
from the drop-
down list box.
When you use one of these encryption algorithms for data
communications, both the sending device and the receiving device
must use the same secret key, which can be used to encrypt and
decrypt the message or to generate and verify a message
authentication code. The DES encryption algorithm uses a 56-bit key.
Triple DES (
3DES
) is a variation on
DES
that uses a 168-bit key. As a
result,
3DES
is more secure than
DES
. It also requires more
processing power, resulting in increased latency and decreased
throughput. This implementation of
AES
uses a 128-bit, 192-bit or
256-bit key.
AES
is faster than
3DES
.
Integrity
Algorithm
Select
SHA1
or
MD5
from the drop-down list box.
MD5
(Message
Digest 5) and
SHA1
(Secure Hash Algorithm) are hash algorithms used
to authenticate packet data. The
SHA1
algorithm is generally
considered stronger than
MD5
, but is slower. Select
MD5
for minimal
security and
SHA1
for maximum security.
Select Diffie-
Hellman Group
for Key
Exchange
You must choose a key group for key exchange in SA setup.
768bit
refers to Diffie-Hellman Group 1 a 768 bit random number.
1024bit
refers to Diffie-Hellman Group 2 a 1024 bit (1Kb) random number.
Other options include
1536
,
2048
, and
3072
bit Diffie-Hellman
groups.
Key Life Time
(Seconds)
Define the length of time before an IKE or IPSec SA automatically
renegotiates in this field. It may range from 1 to 2,000,000,000
seconds.
A short SA Life Time increases security by forcing the two VPN
gateways to update the encryption and authentication keys. However,
every time the VPN tunnel renegotiates, all users accessing remote
resources are temporarily disconnected.
Apply
Click
Apply/Save
to save your changes and return to the
IPSec
screen.
Cancel
Click
Cancel
to exit this screen without saving.
Table 87
Settings > Add/Edit: Auto(IKE)
LABEL
DESCRIPTION
Содержание VSG1435-B101 - V1.10
Страница 2: ......
Страница 8: ...Safety Warnings VSG1435 B101 Series User s Guide 8 ...
Страница 10: ...Contents Overview VSG1435 B101 Series User s Guide 10 ...
Страница 20: ...Table of Contents VSG1435 B101 Series User s Guide 20 ...
Страница 21: ...21 PART I User s Guide ...
Страница 22: ...22 ...
Страница 42: ...Chapter 2 The Web Configurator VSG1435 B101 Series User s Guide 42 ...
Страница 71: ...71 PART II Technical Reference ...
Страница 72: ...72 ...
Страница 78: ...Chapter 5 Network Map and Status Screens VSG1435 B101 Series User s Guide 78 ...
Страница 150: ...Chapter 8 Home Networking VSG1435 B101 Series User s Guide 150 ...
Страница 154: ...Chapter 9 Static Routing VSG1435 B101 Series User s Guide 154 ...
Страница 178: ...Chapter 11 Policy Forwarding VSG1435 B101 Series User s Guide 178 ...
Страница 196: ...Chapter 12 Network Address Translation NAT VSG1435 B101 Series User s Guide 196 ...
Страница 202: ...Chapter 13 Dynamic DNS Setup VSG1435 B101 Series User s Guide 202 ...
Страница 228: ...Chapter 16 Firewall VSG1435 B101 Series User s Guide 228 ...
Страница 234: ...Chapter 18 Parental Control VSG1435 B101 Series User s Guide 234 ...
Страница 282: ...Chapter 25 Traffic Status VSG1435 B101 Series User s Guide 282 ...
Страница 286: ...Chapter 26 IGMP Status VSG1435 B101 Series User s Guide 286 ...
Страница 294: ...Chapter 28 Remote Management VSG1435 B101 Series User s Guide 294 ...
Страница 298: ...Chapter 29 Time Settings VSG1435 B101 Series User s Guide 298 ...
Страница 302: ...Chapter 30 Logs Setting VSG1435 B101 Series User s Guide 302 ...
Страница 318: ...Chapter 34 Troubleshooting VSG1435 B101 Series User s Guide 318 ...
Страница 348: ...Appendix A Setting up Your Computer s IP Address VSG1435 B101 Series User s Guide 348 ...
Страница 358: ...Appendix B IP Addresses and Subnetting VSG1435 B101 Series User s Guide 358 ...
Страница 368: ...Appendix C Pop up Windows JavaScripts and Java Permissions VSG1435 B101 Series User s Guide 368 ...
Страница 384: ...Appendix D Wireless LANs VSG1435 B101 Series User s Guide 384 ...
Страница 412: ...Index VSG1435 B101 Series User s Guide 412 ...