Chapter 11 VPN
The two P-793H v2s in this example can complete negotiation and establish a VPN
tunnel.
Table 51 Matching ID Type and Content Configuration Example
P-793H V2 A
Local ID type: E-mail
Local ID content:
tom@yourcompany.com
Peer ID type: IP
Peer ID content: 1.1.1.2
The two P-793H v2s in this example cannot complete their negotiation because P-
793H v2 B's Local ID type is IP, but P-793H v2 A's Peer ID type is set to E-
mail. An "ID mismatched" message displays in the IPSEC LOG.
Table 52 Mismatching ID Type and Content Configuration Example
P-793H V2 A
Local ID type: IP
Local ID content: 1.1.1.10
Peer ID type: E-mail
Peer ID content: aa@yahoo.com
11.9.10 Pre-Shared Key
A pre-shared key identifies a communicating party during a phase 1 IKE
negotiation (see
"pre-shared" because you have to share it with another party before you can
communicate with them over a secure connection.
11.9.11 Diffie-Hellman (DH) Key Groups
Diffie-Hellman (DH) is a public-key cryptography protocol that allows two parties
to establish a shared secret over an unsecured communications channel. Diffie-
Hellman is used within IKE SA setup to establish session keys. 768-bit (Group 1 -
DH1) and 1024-bit (Group 2 – DH2) Diffie-Hellman groups are supported. Upon
completion of the Diffie-Hellman exchange, the two peers have a shared secret,
but the IKE SA is not authenticated. For authentication, use pre-shared keys.
11.9.12 Telecommuter VPN/IPSec Examples
The following examples show how multiple telecommuters can make VPN
connections to a single P-793H v2 at headquarters. The telecommuters use IPSec
routers with dynamic WAN IP addresses. The P-793H v2 at headquarters has a
static public IP address.
188
P-793H V2 B
Local ID type: IP
Local ID content: 1.1.1.10
Peer ID type: IP
Peer ID content: N/A
Section 11.9.5 on page 184
P-793H V2 B
Local ID type: IP
Local ID content: 1.1.1.2
Peer ID type: E-mail
Peer ID content: tom@yourcompany.com
for more on IKE phases). It is called
P-793H v2 User's Guide