NETGEAR ProSafe FVS336Gv2 Reference Manual page 402

Prosafe dual wan gigabit ssl vpn firewall
Hide thumbs Also See for ProSafe FVS336Gv2:
Table of Contents

Advertisement

ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2
Setting
Description
General
Policy Name
A descriptive name of the IKE policy for identification and management purposes.
This example uses ModeConfigAME_Sales.
Note:
Direction / Type
Responder is automatically selected when you select the Mode Config record in
the Mode Config Record section. This ensures that the VPN firewall responds to
an IKE request from the remote endpoint but does not initiate one.
Exchange Mode
Aggressive mode is automatically selected when you select the Mode Config
record in the Mode Config Record section.
Local
Select Local Gateway
Select a WAN interface from the menu to specify the WAN interface for the local
gateway.
Identifier Type
From the menu, select FQDN.
Note:
defined by an FQDN.
Identifier
Enter an FQDN for the VPN firewall. This example uses router.com.
Remote
Identifier Type
From the menu, select FQDN.
Note:
Identifier
Enter the FQDN for the remote endpoint. This must be an FQDN that is not used
in any other IKE policy. This example uses client.com.
IKE SA Parameters
Encryption Algorithm
To negotiate the security association (SA), from the menu, select the 3DES
algorithm.
Authentication
From the menu, select the SHA-1 algorithm to be used in the VPN header for the
Algorithm
authentication process.
Authentication Method Select Pre-shared key as the authentication method, and enter a key in the
Pre-shared key field.
Pre-shared key
A key with a minimum length of 8 characters and no more than 49 characters. Do
not use a double quote (''), single quote ('), or space in the key. This example uses
H8!spsf3#JYK2!.
Diffie-Hellman (DH)
The DH Group sets the strength of the algorithm in bits. From the menu, select
Group
Group 2 (1024 bit).
SA-Lifetime (sec)
The period in seconds for which the IKE SA is valid. When the period times out,
the next rekeying occurs. The default setting is 28800 seconds (eight hours).
However, for a Mode Config configuration, NETGEAR recommends 3600 seconds
(one hour).
Set Up Virtual Private Networking With IPSec Connections
The name is not supplied to the remote VPN endpoint.
Mode Config requires that the VPN firewall (that is, the local endpoint) is
Mode Config requires that the remote endpoint is defined by an FQDN.
400

Advertisement

Table of Contents
loading

Table of Contents