Planet SG-4800 User Manual page 115

Gigabit ssl vpn security router
Hide thumbs Also See for SG-4800:
Table of Contents

Advertisement

IKE Protocol
Click the shared key generated by IKE to encrypt and authenticate the remote user. If PFS (Perfect Forward
Secrecy) is enabled, the Phase 2 shared key generated during the IKE coordination will conduct further
encryption and authentication. When PFS is enabled, hackers using brute force to capture the key will not be
able to get the Phase 2 key in such a short period of time.
Item
Description
When users check the PFS option, don't forget to activate the PFS function of the VPN
Perfect Forward
device and the VPN Client as well.
Secrecy
 T his option allows users to select Diffie-Hellman groups: Group 1/ Group 2/ Group 5.
Phase 1/ Phase 2
DH Group
 P hase 1/ Phase 2
This option allows users to set this VPN tunnel to use any encryption mode. Note that
this parameter must be identical to that of the remote encryption parameter: DES (64-bit
Encryption
encryption mode), 3DES (128-bit encryption mode), AES (the standard of using security
code to encrypt information). It supports 128-bit, 192-bit, and 256-bit encryption keys.
 T his authentication option allows users to set this VPN tunnel to use any authentication
Phase 1/Phase 2
mode. Note that this parameter must be identical to that of the remote authentication
Authentication
mode: "MD5" or "SHA1".
The life time for this exchange code is set to 28800 seconds (or 8hours) by default. This
Phase 1 SA Life
allows the automatic generation of other exchange password within the valid time of the
Time
VPN connection so as to guarantee security.
The life time for this exchange code is set to 3600 seconds (or 1hours) by default. This
Phase2 SA Life
allows the automatic generation of other exchange password within the valid time of the
Time
VPN connection so as to guarantee security.
Advanced Setting- for IKE Preshareed Key Only
The advanced settings include Main Mode and Aggressive mode. For the Main mode, the default setting is set to
VPN operation mode. The connection is the same to most of the VPN devices.
Gigabit SSL VPN Security Router User's Manual
- 109 -

Advertisement

Table of Contents
loading

Table of Contents