D-Link DIR-825/AC User Manual page 188

Wireless ac1200 dual band gigabit router
Hide thumbs Also See for DIR-825/AC:
Table of Contents

Advertisement

DIR-825/AC Wireless AC1200 Dual Band Gigabit Router
User Manual
Parameter
Enable PFS
Second phase
PFSgroup type
IPsec-SA lifetime
If you need to specify IP addresses of local and remote subnets for creating a tunnel, click the ADD
button in the Tunneled networks section.
Figure 151. The page for adding an IPsec tunnel. The window for adding a tunneled network.
In the line displayed, you can specify the following parameters:
Parameter
Local subnet
Remote subnet
To edit fields in the Tunneled networks section, select the relevant line in the table. In the
opened window, change the needed parameters and click the SAVE button.
To remove a subnet, select the checkbox located to the left of the relevant line in the table and click
the Delete button. Also you can remove a subnet in the editing window.
After configuring all needed settings for the IPsec tunnel, click the APPLY button.
After clicking the APPLY button, the page with the Tunnels and Status sections opens. In the
Status section, the current state of an existing tunnel is displayed.
To edit the parameters of an existing tunnel, in the Tunnels section, select the relevant tunnel in the
table. On the opened page, change the needed parameters and click the APPLY button.
To remove an existing tunnel, select the checkbox located to the left of the relevant line in the table
and click the Delete button. Also you can remove a tunnel on the editing page.
Move the switch to the right to enable the PFS option (Perfect
Forward Secrecy). If the is moved to the right, a new encryption key
exchange will be used for Phase 2. This option increases the security
level of data transfer.
A Diffie-Hellman key group for Phase 2. Select a value from the drop-
down list. The field is available, if the Enable PFS switch is moved
to the right.
The lifetime of IPsec-SA keys in seconds. After the specified period it
is required to renegotiate the keys. Specify 0 if you don't want to limit
the lifetime of the keys.
A local subnet IP address and mask.
A remote subnet IP address and mask.
Page 188 of 222
Configuring via Web-based Interface
Description
Description

Advertisement

Table of Contents
loading

Table of Contents