ZyXEL Communications VMG1312-B10B Series User Manual page 246

Wireless n vdsl2 4-port gateway with usb
Table of Contents

Advertisement

Chapter 20 VPN
Table 93 IPSec VPN: Add
LABEL
Key Life Time
Phase 2
Encryption
Algorithm
Integrity
Algorithm
Diffie-Hellman
Group for Key
Exchange
Key Life Time
DPD Active
Security Protocol - Manual
Key Exchange
Method
246
DESCRIPTION
Define the length of time before an IPSec SA automatically renegotiates in this
field.
A short SA Life Time increases security by forcing the two VPN gateways to
update the encryption and authentication keys. However, every time the VPN
tunnel renegotiates, all users accessing remote resources are temporarily
disconnected.
Select which key size and encryption algorithm to use in the IKE SA. Choices
are:
DES - a 56-bit key with the DES encryption algorithm
3DES - a 168-bit key with the DES encryption algorithm
AES128 - a 128-bit key with the AES encryption algorithm
AES196 - a 196-bit key with the AES encryption algorithm
AES256 - a 256-bit key with the AES encryption algorithm
NULL - no encryption key or algorithm
The Device and the remote IPSec router must use the same key size and
encryption algorithm. Longer keys require more processing power, resulting in
increased latency and decreased throughput.
Select which hash algorithm to use to authenticate packet data. Choices are
MD5, SHA1. SHA is generally considered stronger than MD5, but it is also
slower.
Select which Diffie-Hellman key group you want to use for encryption keys.
Choices for number of bits in the random number are: 768, 1024, 2048, 3072,
4096, 6144, 8192.
Define the length of time before an IPSec SA automatically renegotiates in this
field.
A short SA Life Time increases security by forcing the two VPN gateways to
update the encryption and authentication keys. However, every time the VPN
tunnel renegotiates, all users accessing remote resources are temporarily
disconnected.
Enable Dead Peer Detection (DPD) Active check box if you want the Device to
make sure the remote IPSec router is there before it transmits data through the
IKE SA. The remote IPSec router must support DPD. If the remote IPSec router
does not respond, the Device shuts down the IKE SA.
Select the key exchange method:
Auto(IKE) - Select this to use automatic IKE key management VPN connection
policy.
Manual - Select this option to configure a VPN connection policy that uses a
manual key instead of IKE key management. This may be useful if you have
problems with IKE key management.
Note: Only use manual key as a temporary solution, because it is not as secure as
a regular IPSec SA.
VMG1312-B10B / VMG1312-B30B Series User's Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Vmg1312- b30b series

Table of Contents