ZyXEL Communications ZyWall 10W User Manual page 551

Zywall series internet security gateway
Hide thumbs Also See for ZyWall 10W:
Table of Contents

Advertisement

FIELD
Phase 1
Negotiation
Press [SPACE BAR] to choose from Main or Aggressive and then press
Mode
[ENTER]. See earlier for a discussion of these modes. Multiple SAs
connecting through a secure gateway must have the same negotiation mode.
Authentication
Select Pre-Shared Key to use a pre-shared key to identify the ZyWALL and
Method
the remote IPSec router. A pre-shared key identifies a communicating party
during a phase 1 IKE negotiation. It is called "pre-shared" because you have
to share it with another party before you can communicate with them over a
secure connection.
Select Certificate to identify the ZyWALL and the remote IPSec router by
certificates.
Pre-Shared
ZyWALL gateways authenticate an IKE VPN session by matching pre-shared
Key
keys. Pre-shared keys are best for small networks with fewer than ten nodes.
Enter your pre-shared key here. Enter up to 31 characters. Any character may
be used, including spaces, but trailing spaces are truncated.
Both ends of the VPN tunnel must use the same pre-shared key. You will
receive a "PYLD_MALFORMED" (payload malformed) packet if the same pre-
shared key is not used on both ends.
Certificate
Select the certificate to use for this VPN tunnel. You must have certificates
already configured in the My Certificates screen (see the web configurator
Certificates part for details).
Encryption
The ZyWALL and the remote IPSec router generate an encryption key from
Algorithm
the Diffie-Hellman key exchange. ZyWALL DES encryption algorithm uses a
56-bit key.
Triple DES (3DES), is a variation on DES that uses a 168-bit key. As a result,
3DES is more secure than DES. It also requires more processing power,
resulting in slightly increased latency and decreased throughput.
This implementation of AES uses a 128-bit key. AES is faster than 3DES.
Press [SPACE BAR] to choose from DES, 3DES or AES and then press
[ENTER].
Authentication
MD5 (Message Digest 5) and SHA1 (Secure Hash Algorithm) are hash
Algorithm
algorithms used to authenticate packet data. The SHA1 algorithm is generally
considered stronger than MD5, but is slightly slower.
Press [SPACE BAR] to choose from SHA1 or MD5 and then press [ENTER].
VPN/IPSec Setup
Table 40-3
Menu 27.1.1.1: IKE Setup
DESCRIPTION
ZyWALL Series Internet Security Gateway
EXAMPLE
Main
DES
SHA1
40-13

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zywall 30wZywall 100Zywall 50

Table of Contents