Editing A Component Bb; Figure 143 Component Bbs Added - ZyXEL Communications Vantage CNM User Manual

Centralized network management
Hide thumbs Also See for Vantage CNM:
Table of Contents

Advertisement

Table 112 Building Block > Component BB > Add > VPN1.0
TYPE
Perfect Forward Secrecy
(PFS)
Apply
Reset
The following screen then shows the component BBs you added. Click a Name hyperlink to
edit the BB.

Figure 143 Component BBs Added

18.5.2 Editing a Component BB

Click the Name hyperlink in the component BB summary screen as shown in
page 272
to edit a component BB.
Chapter 18 Building Blocks (BBs)
DESCRIPTION
Choose whether to enable Perfect Forward Secrecy (PFS) using Diffie-
Hellman public-key cryptography. Enabling PFS means that the key is
transient. A brand new key using a new Diffie-Hellman exchange replaces
the key for each new IPSec SA.
With PFS enabled, if one key is compromised, previous and subsequent
keys are not compromised, because subsequent keys are not derived
from previous keys. The (time-consuming) Diffie-Hellman exchange is the
trade-off for this extra security.
Disabling PFS means new authentication and encryption keys are derived
from the same root secret (which may have security implications in the
long run) but allows faster SA setup (by bypassing the Diffie-Hellman key
exchange).
Click Apply to create the BB. This BB is then displayed in the component
BB summary screen.
Click Reset to begin configuring the screen afresh.
Vantage CNM User's Guide
Figure 143 on
272

Advertisement

Table of Contents
loading

Table of Contents