ZyXEL Communications USG40 User Manual page 105

Zywall/usg series
Hide thumbs Also See for USG40:
Table of Contents

Advertisement

Figure 80 VPN for Configuration Provisioning Advanced Wizard: Phase 1 Settings
• Secure Gateway: Any displays in this field because it is not configurable in this wizard. It allows
incoming connections from the ZyWALL/USG IPSec VPN Client.
• My Address (interface): Select an interface from the drop-down list box to use on your
ZyWALL/USG.
• Negotiation Mode:This displays Main or Aggressive:
• Main encrypts the ZyWALL/USG's and remote IPSec router's identities but takes more time to
establish the IKE SA
• Aggressive is faster but does not encrypt the identities.
The ZyWALL/USG and the remote IPSec router must use the same negotiation mode. Multiple SAs
connecting through a secure gateway must have the same negotiation mode.
• Encryption Algorithm: 3DES and AES use encryption. The longer the key, the higher the
security (this may affect throughput). Both sender and receiver must know the same secret key,
which can be used to encrypt and decrypt the message or to generate and verify a message
authentication code. The DES encryption algorithm uses a 56-bit key. Triple DES (3DES) is a
variation on DES that uses a 168-bit key. As a result, 3DES is more secure than DES. It also
requires more processing power, resulting in increased latency and decreased throughput.
AES128 uses a 128-bit key and is faster than 3DES. AES192 uses a 192-bit key and AES256 uses
a 256-bit key.
• Authentication Algorithm: MD5 (Message Digest 5) and SHA (Secure Hash Algorithm) are
hash algorithms used to authenticate packet data. MD5 gives minimal security. SHA1 gives
higher security and SHA256 gives the highest security. The stronger the algorithm, the slower it
is.
• Key Group: DH5 is more secure than DH1 or DH2 (although it may affect throughput). DH1
(default) refers to Diffie-Hellman Group 1 a 768 bit random number. DH2 refers to Diffie-Hellman
Group 2 a 1024 bit (1Kb) random number. DH5 refers to Diffie-Hellman Group 5 a 1536 bit
random number.
• SA Life Time: Set how often the ZyWALL/USG renegotiates the IKE SA. A short SA life time
increases security, but renegotiation temporarily disconnects the VPN tunnel.
• Authentication Method: Select Pre-Shared Key to use a password or Certificate to use one
of the ZyWALL/USG's certificates.
Chapter 4 Easy Mode
ZyWALL/USG Series User's Guide
105

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents