NETGEAR UTM25-100NAS - Prosecure Utm Appliance 25U No Sub Included Reference Manual page 255

Prosecure unified threat management
Table of Contents

Advertisement

ProSecure Unified Threat Management UTM10 or UTM25 Reference Manual
Table 7-15. Add Mode Config Record Settings (continued)
Item
WINS Server
DNS Server
Traffic Tunnel Security Level
Note: Generally, the default setting work well for a Mode Config configuration.
PFS Key Group
SA Lifetime
Encryption Algorithm From the pull-down menu, select one of the following five algorithms to
Integrity Algorithm
Local IP Address
Local Subnet Mask
Virtual Private Networking Using IPsec Connections
Description (or Subfield and Description)
If there is a WINS server on the local network, enter its IP address in the
Primary field. You can enter the IP address of a second WINS server in the
Secondary field.
Enter the IP address of the DNS server that is used by remote VPN clients in the
Primary field. You can enter the IP address of a second DNS server in the
Secondary field.
Select this checkbox to enable Perfect Forward Secrecy (PFS), and then select
a Diffie-Hellman (DH) group from the pull-down menu. The DH Group sets the
strength of the algorithm in bits. The higher the group, the more secure the
exchange. From the pull-down menu, select one of the following three
strengths:
• Group 1 (768 bit).
• Group 2 (1024 bit). This is the default setting.
• Group 5 (1536 bit).
The lifetime of the Security Association (SA) is the period or the amount of
transmitted data after which the SA becomes invalid and must be renegotiated.
From the pull-down menu, select how the SA lifetime is specified:
• Seconds. In the SA Lifetime field, enter a period in seconds. The minimum
value is 300 seconds. The default value is 3600 seconds.
• KBytes. In the SA Lifetime field, enter a number of kilobytes. The minimum
value is 1920000 KB.
negotiate the security association (SA):
• DES. Data Encryption Standard (DES)
• 3DES. Triple DES. This is the default algorithm.
• AES-128. Advanced Encryption Standard (AES) with a 128-bits key size.
• AES-192. AES with a 192-bits key size.
• AES-256. AES with a 256-bits key size.
From the pull-down menu, select one of the following two algorithms to be used
in the VPN header for the authentication process:
• SHA-1. Hash algorithm that produces a 160-bit digest. This is the default
setting.
• MD5. Hash algorithm that produces a 128-bit digest.
The local IP address to which remote VPN clients have access. Typically, this is
the UTM's LAN subnet, such as 192.168.1.0.
Note: If you do not specify a local IP address, the
used.
The local subnet mask. Typically, this is 255.255.255.0.
v1.0, September 2009
UTM
's default LAN subnet is
7-45

Advertisement

Table of Contents
loading

This manual is also suitable for:

Prosecure utm10Prosecure utm25

Table of Contents