Pre-Shared Key; Diffie-Hellman (Dh) Key Groups - ZyXEL Communications SBG3500-N000 User Manual

Sbg3500-n series wireless n fiber wan small business gateway
Hide thumbs Also See for SBG3500-N000:
Table of Contents

Advertisement

The two SBG3500-N Seriess in this example cannot complete their negotiation because SBG3500-N
Series B's Local ID type is IP, but SBG3500-N Series A's Remote ID type is set to E-mail. An "ID
mismatched" message displays in the IPSEC LOG.
Table 111 Mismatching ID Type and Content Configuration Example
SBG3500-N SERIES A
Local ID type: IP
Local ID content: 1.1.1.10
Remote ID type: User-FQDN
Remote ID content: aa@yahoo.com

22.7.8 Pre-Shared Key

A pre-shared key identifies a communicating party during a phase 1 IKE negotiation (see
22.7.3 on page 289
with another party before you can communicate with them over a secure connection.

22.7.9 Diffie-Hellman (DH) Key Groups

Diffie-Hellman (DH) is a public-key cryptography protocol that allows two parties to establish a
shared secret over an unsecured communications channel. Diffie-Hellman is used within IKE SA
setup to establish session keys. 768-bit, 1024-bit 1536-bit, 2048-bit, and 3072-bit Diffie-Hellman
groups are supported. Upon completion of the Diffie-Hellman exchange, the two peers have a
shared secret, but the IKE SA is not authenticated. For authentication, use pre-shared keys.
Chapter 22 IPSec VPN
for more on IKE phases). It is called "pre-shared" because you have to share it
SBG3500-N Series User's Guide
293
SBG3500-N SERIES B
Local ID type: IP
Local ID content: 1.1.1.2
Remote ID type: IP
Remote ID content: 1.1.1.0
Section

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sbg3500-nb00

Table of Contents