ZyXEL Communications ZyWall USG 50-H Series User Manual page 73

Unified security gateway
Table of Contents

Advertisement

Figure 38 VPN Advanced Wizard: Step 3
The following table describes the labels in this screen.
Table 18 VPN Advanced Wizard: Step 3
LABEL
Phase 1
Setting
Secure
Gateway
My Address
(interface)
Negotiation
Mode
Encryption
Algorithm
Authentication
Algorithm
Key Group
ZyWALL USG 50-H User's Guide
DESCRIPTION
If Any displays in this field, it is not configurable for the chosen scenario.
If this field is configurable, enter the WAN IP address or domain name of the remote
IPSec router (secure gateway) in the field below to identify the remote IPSec router
by its IP address or a domain name. Set this field to 0.0.0.0 if the remote IPSec
router has a dynamic WAN IP address.
Select an interface from the drop-down list box to use on your ZyWALL.
Select Main for identity protection. Select Aggressive to allow more incoming
connections from dynamic IP addresses to use separate passwords.
Note: Multiple SAs (security associations) connecting through a
secure gateway must have the same negotiation mode.
When DES is used for data communications, both sender and receiver must know
the same secret key, which can be used to encrypt and decrypt the message or to
generate and verify a message authentication code. The DES encryption algorithm
uses a 56-bit key. Triple DES (3DES) is a variation on DES that uses a 168-bit key.
As a result, 3DES is more secure than DES. It also requires more processing power,
resulting in increased latency and decreased throughput. AES128 uses a 128-bit
key and is faster than 3DES. AES192 uses a 192-bit key and AES256 uses a 256-bit
key. Select Null to have no encryption.
MD5 (Message Digest 5) and SHA1 (Secure Hash Algorithm) are hash algorithms
used to authenticate packet data. The SHA1 algorithm is generally considered
stronger than MD5, but is slower. Select MD5 for minimal security and SHA1 for
maximum security.
You must choose a key group for phase 1 IKE setup. DH1 (default) refers to Diffie-
Hellman Group 1 a 768 bit random number. DH2 refers to Diffie-Hellman Group 2 a
1024 bit (1Kb) random number. DH5 refers to Diffie-Hellman Group 5 a 1536 bit
random number.
Chapter 4 Wizard Setup
73

Advertisement

Table of Contents
loading

Table of Contents