CyberGuard SG300 User Manual page 205

Cyberguard sg series
Table of Contents

Advertisement

Note
Select an interface other than the default gateway when you have more than one Internet
connection or have configured aliased Internet interfaces, and require the IPSec tunnel to
run on an interface other than the default gateway.
Select the type of keying for the tunnel to use. The CyberGuard SG appliance supports
the following types of keying:
Main Mode automatically exchanges encryption and authentication keys and
protects the identities of the parties attempting to establish the tunnel.
This mode is the most secure, but difficult to configure in environments where one
end has a dynamic Internet IP address.
Aggressive Mode automatically exchanges encryption and authentication keys
and uses less messages in the exchange when compared to main mode.
Aggressive mode is typically used to allow parties that are configured with a
dynamic IP address and a preshared secret to connect or if the CyberGuard SG
appliance or the remote party is behind a NAT device.
This mode is less secure than main mode, but much easier to configure in
environments where one end has a dynamic Internet IP address. When using this
mode, ensure to use a long and particularly hard to guess preshared secret.
Manual Keying requires the encryption and authentication keys to be specified.
This mode is not recommended unless connecting to a legacy device that does
not support main or aggressive modes.
It is hard to identify problems Manual keying requires regular user intervention in
the form of manual key changes, and it is hard to identify
In this example, select the Aggressive Mode option.
An IPSec tunnel connects two endpoints. These endpoints may be of different types,
however some configurations are preferable to others with regards to ease of
configuration and security (i.e. main vs. aggressive mode) and robustness (i.e. relying on
an external DNS server). The following is a list of configurations, from most to least
preferable:
1. static IP address to static IP address
2. dynamic IP address to static IP address (as detailed in this example)
Virtual Private Networking
201

Hide quick links:

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the SG300 and is the answer not in the manual?

Questions and answers

This manual is also suitable for:

Sg530Sg550Sg565Sg570Sg575Sg580 ... Show all

Table of Contents