D-Link DVG-5402G/GF User Manual page 149

Wireless ac1200 wave 2 mu-mimo dual band gigabit router with fiber wan port, 3g/lte support, 2 fxs ports, and usb port
Table of Contents

Advertisement

DVG-5402G/GF Wireless AC1200 Wave 2 MU-MIMO Dual
Band Gigabit Router with Fiber WAN Port, 3G/LTE Support,
2 FXS Ports, and USB Port
User Manual
Parameter
Aggressive Mode
IKE version
Second phase
encryption algorithm
Encryption mode
Hashing algorithm
Size of hash
Hashing mode
Enable PFS
Second phase
DHgroup type
IPsec-SA lifetime
To specify IP addresses of local and remote subnets for this tunnel, click the ADD button (
the Tunneled Networks section.
Move the switch to the right to enable the aggressive mode for mutual
authentication of the parties. Such a setting accelerates the connection
establishment, but reduces its security.
IKE (Internet Key Exchange) is a protocol of keys exchange between
two hosts of VPN connections. Select a version of the protocol from
the drop-down list.
The Second Phase
Select an available encryption algorithm from the drop-down list.
Select an encryption mode from the drop-down list.
Select a hashing algorithm from the drop-down list.
The length of the hash in bits.
Select a hashing mode from the drop-down list.
Move the switch to the right to enable the PFS option (Perfect
Forward Secrecy). If the switch is moved to the right, a new
encryption key exchange will be used for the Second Phase. This
option enhances the security level of data transfer, but increases the
load on DVG-5402G/GF.
A Diffie-Hellman key group for the Second Phase. Select a value from
the drop-down list. The drop-down list is available if the Enable PFS
switch is moved to the right.
The lifetime of the Second Phase keys in seconds. After the specified
period it is required to renegotiate the keys. The value specified in this
field should be greater than zero.
Page 149 of 352
Configuring via Web-based Interface
Description
) in

Advertisement

Table of Contents
loading

Table of Contents