Viewing Sa Monitor - ZyXEL Communications P-793H v3 User Manual

P-79x series g.shdsl.bis broadband gateway
Hide thumbs Also See for P-793H v3:
Table of Contents

Advertisement

Table 49 Security > VPN > Setup > Edit > Advanced Setup (continued)
LABEL
Authentication
Algorithm
SA Life Time
(Seconds)
Encapsulation
Perfect Forward
Secrecy (PFS)
Back
Apply
Cancel

13.5 Viewing SA Monitor

Click Security > VPN > Monitor to open the screen as shown. Use this screen to display and
manage active VPN connections.
A Security Association (SA) is the group of security settings related to a specific VPN tunnel. This
screen displays active VPN connections. Use Refresh to display active VPN connections. This
screen is read-only. The following table describes the fields in this tab.
When there is outbound traffic but no inbound traffic, the SA times out automatically after two
minutes. A tunnel with no outbound or inbound traffic is "idle" and does not timeout until the SA
lifetime period expires. See
an IPSec SA when the SA lifetime expires, even if there is no traffic.
Chapter 13 VPN
DESCRIPTION
Select SHA1 or MD5 from the drop-down list box. MD5 (Message Digest 5) and
SHA1 (Secure Hash Algorithm) are hash algorithms used to authenticate packet
data. The SHA1 algorithm is generally considered stronger than MD5, but is
slower. Select MD5 for minimal security and SHA-1 for maximum security.
Define the length of time before an IKE SA automatically renegotiates in this
field. It may range from 60 to 3,000,000 seconds (almost 35 days).
A short SA Life Time increases security by forcing the two VPN gateways to
update the encryption and authentication keys. However, every time the VPN
tunnel renegotiates, all users accessing remote resources are temporarily
disconnected.
Select Tunnel mode or Transport mode from the drop-down list box.
Perfect Forward Secrecy (PFS) is disabled (NONE) by default in phase 2 IPSec
SA setup. This allows faster IPSec setup, but is not so secure. Choose DH1 or
DH2 from the drop-down list box to enable PFS. DH1 refers to Diffie-Hellman
Group 1 a 768 bit random number. DH2 refers to Diffie-Hellman Group 2 a 1024
bit (1Kb) random number (more secure, yet slower).
Click Back to return to the previous screen.
Click Apply to save your changes back to the P-79X and return to the VPN-IKE
screen.
Click Cancel to return to the VPN-IKE screen without saving your changes.
Section 13.6.7 on page
P-79X Series User's Guide
138
144on keep alive to have the P-79X renegotiate

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

P-792h v3P-791r v3

Table of Contents