ZyXEL Communications ZyWALL 5 User Manual page 65

Internet security appliance
Hide thumbs Also See for ZyWALL 5:
Table of Contents

Advertisement

LABEL
Encryption Algorithm
Authentication
Algorithm
SA Life Time
(Seconds)
Perfect Forward
Secret (PFS)
Back
Next
3.5.5 VPN Status Summary
This read-only screen shows the status of the current VPN setting. Use the summary table to check
whether what you have configured is correct.
Wizard Setup
Table 3-11 VPN Wizard : IPSec Setting
When DES is used for data communications, both sender and receiver must know the
same secret key, which can be used to encrypt and decrypt the message or to
generate and verify a message authentication code. The DES encryption algorithm
uses a 56-bit key. Triple DES (3DES) is a variation on DES that uses a 168-bit key.
As a result, 3DES is more secure than DES. It also requires more processing power,
resulting in increased latency and decreased throughput. This implementation of AES
uses a 128-bit key. AES is faster than 3DES. Select NULL to set up a tunnel without
encryption. When you select NULL, you do not enter an encryption key.
MD5 (Message Digest 5) and SHA1 (Secure Hash Algorithm) are hash algorithms
used to authenticate packet data. The SHA1 algorithm is generally considered
stronger than MD5, but is slower. Select MD5 for minimal security and SHA-1 for
maximum security.
Define the length of time before an IKE SA automatically renegotiates in this field. The
minimum value is 180 seconds.
A short SA Life Time increases security by forcing the two VPN gateways to update
the encryption and authentication keys. However, every time the VPN tunnel
renegotiates, all users accessing remote resources are temporarily disconnected.
Perfect Forward Secret (PFS) is disabled (None) by default in phase 2 IPSec SA
setup. This allows faster IPSec setup, but is not so secure.
Select DH1 or DH2 to enable PFS. DH1 refers to Diffie-Hellman Group 1 a 768 bit
random number. DH2 refers to Diffie-Hellman Group 2 a 1024 bit (1Kb) random
number (more secure, yet slower).
Click Back to return to the previous screen.
Click Next to continue.
ZyWALL 5 Internet Security Appliance
DESCRIPTION
3-17

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents