VR-200 16-Port Multi-WAN VPN Router
• 112 •
encrypt/decrypt ESP packets. DES is 56-bit encryption and 3DES is 168-bit
encryption. In addition, AES includes three types of encryptions, AES-128, AES-192,
and AES-256. Both sides must use the same Encryption method. 3DES or AES is
recommended because it is more secure. If users enable the AH Hash Algorithm in
Advanced, it’s recommended to select Null to disable encrypt/decrypt ESP packets
in Phase 2 for most users, but both sides must use the same setting.
z
Phase 2 Authentication:
There are two methods of authentication, MD5 and SHA.
The Authentication method determines a method to authenticate the ESP packets.
Both sides must use the same Authentication method. MD5 is a one-way hashing
algorithm that produces a 128-bit digest. SHA is a one-way hashing algorithm that
produces a 160-bit digest. If users enable the AH Hash Algorithm in Advanced, it’s
recommended to select Null to disable authentication of the ESP packets in Phase 2
for most users, but both sides must use the same setting.
z
Phase 2 SA Life Time:
This field allows you to configure the length of time a VPN
tunnel is active in Phase 2. The default value is 3,600 seconds.
z
Preshared Key:
The character and hexadecimal values are acceptable in this field,
e.g. "My_@123" or "4d795f40313233." The maximum entry of this filed is 30-digit.
Both sides must use the same Pre-shared Key. It’s recommended to change
Preshared keys regularly to maximize VPN security.
Clink the
Apply
button to save the settings or click the
Cancel
button to undo the changes.
Advanced
For most users, the settings on the VPN page should be satisfactory. This device provides an
advanced IPSec setting page for some special users such as reviewers. Clicking the
"Advanced" will link you to that page. Advanced settings are only for IKE with Preshared Key
mode of IPSec.