ZyXEL Communications NBG-5715 User Manual page 135

32” class 31.5” diagonal
Hide thumbs Also See for NBG-5715:
Table of Contents

Advertisement

Current ZyXEL implementation assumes identical outgoing and incoming SPIs.
18.5.2.2 IPSec SA Using Manual Keys
You might set up an IPSec SA using manual keys when you want to establish a VPN tunnel quickly,
for example, for troubleshooting. You should only do this as a temporary solution, however,
because it is not as secure as a regular IPSec SA.
In IPSec SAs using manual keys, the NBG5715 and remote IPSec router do not establish an IKE SA.
They only establish an IPSec SA. As a result, an IPSec SA using manual keys has some
characteristics of IKE SA and some characteristics of IPSec SA. There are also some differences
between IPSec SA using manual keys and other types of SA.
18.5.2.3 IPSec SA Proposal Using Manual Keys
In IPSec SA using manual keys, you can only specify one encryption algorithm and one
authentication algorithm. There is no DH key exchange, so you have to provide the encryption key
and the authentication key the NBG5715 and remote IPSec router use.
Note: The NBG5715 and remote IPSec router must use the same encryption key and
authentication key.
NBG5715 User's Guide
Chapter 18 IPSec VPN
135

Advertisement

Table of Contents
loading

Table of Contents