HP R100-Series Configuration And Administration Manual page 76

Wireless vpn routers
Hide thumbs Also See for R100-Series:
Table of Contents

Advertisement

If ID_FQDN or ID_USER_FQDN (fully-qualified domain name) is selected, enter the
name for the Remote Party ID in the box next to the list. For example, an FQDN name
could be mycompany.com, and a user FQDN could be a mail address, such as
my_name@mycompany.com. This name must be unique for each connection rule that
you create.
Remote Network Address: Enter the IPv4 address of the remote network.
Remote Subnet Mask: Enter the subnet mask for the remote network.
Local Secure Group
Local Party ID: Enter the identifier of the local secure group.
Network Address: The network address of the local secure group is usually the network
address of the local network.
Subnet Mask: Enter the subnet mask for the local network.
Phase I IKE Parameters
Key Management: Select either IKE Main Mode or IKE Aggressive Mode as the
Internet Key Exchange (IKE) method. Note that the Main Mode is more secure but slower,
and Aggressive Mode is less secure but faster.
Hash Algorithm: Select either MD5 or SHA1 as the algorithm to use for IPSec
authentication.
Encrypt Algorithm: Select an encryption algorithm from the list. Both authentication and
encryption algorithms must be the same on the router and remote host.
Key lifetime: Sets the amount of time that the keys are valid, after which they are
renewed.
Diffie-Hellman Group: Select one of the groups to use for the Diffie-Hellman key
exchange.
Pre-shared Key: Enter the same key on the router and the remote VPN gateway or
client. Do not use these characters: ` " & ' # \
Phase II IPSec Parameters
Authentication Algorithm: Select either MD5 or SHA1 as the algorithm to use for
IPSec authentication.
Encrypt Algorithm: Select an encryption algorithm from the list. Both authentication and
encryption algorithms must be the same on the router and remote host.
Key lifetime: Sets the amount of time that the keys are valid, after which they are
renewed.
PFS: Select for Perfect Forward Secrecy (PFS). The Diffie-Hellman Group options then
become available. The use of PFS is optional, enabling PFS adds another layer of
encryption security.
Diffie-Hellman Group: Select one of the groups to use for the Diffie-Hellman key
exchange.
IKE Keep Alive: Enables the router to send IKE keep-alive packets so that the VPN
connection remains open even when there is no activity.
76
VPN configuration

Advertisement

Table of Contents
loading

Table of Contents