afterwards. In PKI server mode the router represents the Certificate Authority and
issues the certificates for remote peers.
IKE Proposal
This section can be used to configure the phase 1 settings:
Negotiation mode: Choose the desired negotiation mode. Preferably, main mode should
be used but aggressive mode might be applicable when dealing with dynamic
endpoint addresses.
Encryption algorithm: The desired IKE encryption method (we recommend AES256)
Authentication algorithm: The desired IKE authentication method (we prefer SHA1
over MD5)
IKE Diffie-Hellman Group: The IKE Diffie-Hellman Group
SA life time: The lifetime of Security Associations
Perfect Forward Secrecy: Specifies whether Perfect Forward Secrecy (PFS) should be
used. This feature increases security as PFS avoids penetration of the key-exchange
protocol and prevents compromisation of previous keys.
IPsec Proposal
This section can be used to configure the phase 2 settings:
Encapsulation mode: The desired encapsulation mode (Tunnel or Transport)
IPsec protocol: The desired IPsec protocol (AH or ESP)
Encryption algorithm: The desired IKE encryption method (we recommend AES256)
Authentication algorithm: The desired IKE authentication method (we prefer SHA1
over MD5)
SA life time: The lifetime of Security Associations
Networks
When creating Security Associations, IPsec will keep track of routed networks within
the tunnel. Packets will be only transmitted when a valid SA with matching source and
destination network is present. Therefore, you may need to specify the networks right
and left of the endpoints by applying the following settings:
Local network address: The address of your local area network
Local network mask: The netmask of your local area network
Peer network address: The address of the remote network behind the peer
Peer network mask: The netmask of the remote network behind the peer
NAT address: Optionally, you can apply NAT (masquerading) for packets coming from
a different local network. The NAT address must reside in the network previously
specified as local network.
NB2700 User Manual
66
Need help?
Do you have a question about the NB2700 and is the answer not in the manual?