NETGEAR FVS336Gv3 Reference Manual page 389

Prosafe dual wan gigabit ssl vpn firewall
Hide thumbs Also See for FVS336Gv3:
Table of Contents

Advertisement

ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv3
Setting
Auto Policy Parameters
Note:
These fields apply only when you select Manual Policy from the Policy Type menu.
SA Lifetime
Encryption Algorithm
Integrity Algorithm
PFS Key Group
Select IKE Policy
10.
Click the Apply button.
Your settings are saved. The VPN policy is added to the List of VPN Policies table.
Change a VPN Policy
The following procedure describes how to change an existing VPN policy that was added
either automatically or manually.
To change a VPN policy:
1.
On your computer, launch an Internet browser.
Description
The lifetime of the security association (SA) is the period or the amount of
transmitted data after which the SA becomes invalid and must be renegotiated.
From the SA Lifetime menu on the right, select how you must specify the SA
lifetime in the SA Lifetime field on the left:
Seconds. In the SA Lifetime field, enter a period in seconds. The minimum
value is 300 seconds. The default setting is 3600 seconds.
KBytes. In the SA Lifetime field, enter a number of kilobytes. The minimum
value is 1920000 KB.
From the menu, select one algorithm to negotiate the security association (SA):
3DES. Triple DES. This is the default algorithm.
None. No encryption algorithm.
DES. Data Encryption Standard (DES).
AES-128. Advanced Encryption Standard (AES) with a 128-bit key size.
AES-192. AES with a 192-bit key size.
AES-256. AES with a 256-bit key size.
From the menu, select the algorithm to be used in the VPN header for the
authentication process:
SHA-1. Hash algorithm that produces a 160-bit digest. This is the default
setting.
MD5. Hash algorithm that produces a 128-bit digest.
Select the PFS Key Group check box on the left to enable Perfect Forward
Secrecy (PFS and select a Diffie-Hellman (DH) group from the corresponding
menu on the right. The DH Group sets the strength of the algorithm in bits. The
higher the group, the more secure the exchange. From the menu, select the
strength:
Group 1 (768 bit).
Group 2 (1024 bit). This is the default setting.
Group 5 (1536 bit).
Select an existing IKE policy that defines the characteristics of the Phase-1
negotiation.
To display the selected IKE policy, click the View Selected button.
Set Up Virtual Private Networking With IPSec Connections
389

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents