Pre-Shared Key; Diffie-Hellman (Dh) Key Groups; Telecommuter Vpn/Ipsec Examples; Table 51 Matching Id Type And Content Configuration Example - ZyXEL Communications P-793H User Manual

G.shdsl.bis bonded broadband gateway
Hide thumbs Also See for P-793H:
Table of Contents

Advertisement

Chapter 11 VPN
The two P-793H v2s in this example can complete negotiation and establish a VPN
tunnel.

Table 51 Matching ID Type and Content Configuration Example

P-793H V2 A
Local ID type: E-mail
Local ID content:
tom@yourcompany.com
Peer ID type: IP
Peer ID content: 1.1.1.2
The two P-793H v2s in this example cannot complete their negotiation because P-
793H v2 B's Local ID type is IP, but P-793H v2 A's Peer ID type is set to E-
mail. An "ID mismatched" message displays in the IPSEC LOG.

Table 52 Mismatching ID Type and Content Configuration Example

P-793H V2 A
Local ID type: IP
Local ID content: 1.1.1.10
Peer ID type: E-mail
Peer ID content: aa@yahoo.com

11.9.10 Pre-Shared Key

A pre-shared key identifies a communicating party during a phase 1 IKE
negotiation (see
"pre-shared" because you have to share it with another party before you can
communicate with them over a secure connection.

11.9.11 Diffie-Hellman (DH) Key Groups

Diffie-Hellman (DH) is a public-key cryptography protocol that allows two parties
to establish a shared secret over an unsecured communications channel. Diffie-
Hellman is used within IKE SA setup to establish session keys. 768-bit (Group 1 -
DH1) and 1024-bit (Group 2 – DH2) Diffie-Hellman groups are supported. Upon
completion of the Diffie-Hellman exchange, the two peers have a shared secret,
but the IKE SA is not authenticated. For authentication, use pre-shared keys.

11.9.12 Telecommuter VPN/IPSec Examples

The following examples show how multiple telecommuters can make VPN
connections to a single P-793H v2 at headquarters. The telecommuters use IPSec
routers with dynamic WAN IP addresses. The P-793H v2 at headquarters has a
static public IP address.
188
P-793H V2 B
Local ID type: IP
Local ID content: 1.1.1.10
Peer ID type: IP
Peer ID content: N/A
Section 11.9.5 on page 184
P-793H V2 B
Local ID type: IP
Local ID content: 1.1.1.2
Peer ID type: E-mail
Peer ID content: tom@yourcompany.com
for more on IKE phases). It is called
P-793H v2 User's Guide

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

P-793h v2

Table of Contents