Planet mh-5000 User Manual page 83

Hide thumbs Also See for mh-5000:
Table of Contents

Advertisement

MH-5000 User Manual
SA Life Time
Perfect Forward
Secrecy(PFS)
Step 5.
Remind to add a Firewall rule
After finishing IPSec rule settings, we need to add
a firewall rule. Here system shows a window
message to remind you of adding a firewall rule.
Just press the OK button to add a firewall rule.
Step 6.
Add a Firewall rule
Beforehand, please make sure that the Firewall is
enabled. Select WAN1-to-LAN1 to display the
rules of this direction. The default action of this
direction is Block with Logs. We have to allow the
VPN traffic from the WAN1 side to enter our LAN1
side. So we click the Insert button to add a
Firewall rule before the default rule.
Set the IPSec SA lifetime. A value of 0 means
IKE SA negotiation never times out. See
Chapter 9 for details.
Enabling PFS means that the key is transient.
This extra setting will cause more security.
Table 10-5 Setup Advanced feature in the IPSec IKE rule
ADVANCED SETTINGS > VPN Settings > IPSec > IKE > Add
ADVANCED SETTINGS > Firewall > Edit Rules
76
Virtual Private Network – IPSec
0 ~ 9999999999
sec/min/hour
None / DH1 / DH2 /
DH5
Chapter 10
28800 sec
DH1

Advertisement

Table of Contents
loading

Table of Contents