P a g e
|
91
GWN7000 User Manual
Version 1.0.6.28
•
SSL + User Auth:
Requires both certificate and username
/ password. Each user has a unique client configuration
that includes their personal certificate and key.
Most secure, as there are multiple factors of authentication
(TLS Key and Certificate that the user has, and the
username/password they know).
Encryption Algorithm
Choose the encryption algorithm from the drop-down list, in order to
encrypt data so that the receiver can decrypt it using the same
algorithm.
Digest Algorithm
Choose the digest algorithm from the drop-down list, which will
uniquely identify the data to provide data integrity and ensure that
the receiver has an unmodified data from the one sent by the original
host.
TLS Authentication
This option uses a static Pre-Shared Key (PSK) that must be
generated in advance and shared among all peers.
This feature adds extra protection to the TLS channel by requiring
that incoming packets have a valid signature generated using the
PSK key.
TLS Pre-Shared Key
Enter the generated TLS Pre-Shared Key when using TLS
Authentication.
Routes
This feature allows specifying and adding custom routes.
Don’t Pull Routes
If enabled, client will ignore routes pushed by the server.
IP Masquerading
This feature is a form of network address translation (NAT) which
allows internal computers with no known address outside their
network, to communicate to the outside. It allows one machine to act
on behalf of other machines.
LZO Compression
LZO encoding provides a very high compression ratio with good
performance. LZO encoding works especially well for CHAR and
VARCHAR columns that store very long character strings.
Allow Peer to Change IP
Allow remote change the IP and/or Port, often applicable to the
situation when the remote IP address changes frequently.
CA Certificate
Click on “Upload” and select the “CA” certificate generated
previously on this guide.
Client Certificate
Click on “Upload” and select the “Client Certificate” generated
previously on this guide.