VPN advanced configuration
175
Configuration Guide
Encryption
Select the IPSec Encryption. Select one of the following options:
•
null - traffic is not encrypted.
•
Data Encryption Standard (DES) – a standard for encrypting data that
uses a 64 bit key to encrypt data, but only 56 bits are used. This
standard is considered inadequate for data protection.
•
Triple Data Encryption Standard (3DES) – processes each block of
data using a different key each time, resulting in a significantly more
secure message.
•
Advanced Encryption Standard (AES128, AES192, AES256) – has a
fixed block size of 128 bits and a key size of 128, 192 or 256 bits. Due
to the fixed block size of 128 bits, AES operates on a 4x4 array of
bytes.
Select DES if you require network speed.
Select 3-DES if you require network security.
Authentication
Select the preferred authentication method. Select one of the following:
•
None - indicates that no authentication method is required.
•
HMAC-MAC5 - the message authentication code is calculated using
the MD5 cryptographic hash function. This cryptographic hash function
has some additional security properties with a 128-bit hash value,
which is commonly used to check the integrity of files.
•
HMAC-SHA1 - the message authentication code is calculated using
the SHA1 algorithm. This cryptographic hash function computes a
condensed digital representation to a high degree of probability.
Preferred Forward Secrecy
Select the Preferred Forward Secrecy (PFS). Select one of the following
options:
•
None - IKE does not use any PFS.
•
PFS Group 1 - IKE uses a 768-bit Diffie-Hellman Prime modules group
for performing the new Diffie-Hellman exchange.
•
PFS Group 2 - IKE uses a 1024-bit Diffie-Hellman Prime modules
group for performing the new Diffie-Hellman exchange.
•
PFS Group 5 - IKE uses a 1536-bit Diffie-Hellman Prime modules
group for performing the new Diffie-Hellman exchange.
Life Time
Select the life time unit. Select one of seconds, minutes, or hours.
Life Time Value
Type the life time value.
The range is 5 minutes to 8 hours.
Variable
Value
Summary of Contents for BSG12aw 1.0
Page 14: ...14 Introduction NN47928 500 NN47928 500 ...
Page 22: ...22 WAN configuration NN47928 500 NN47928 500 ...
Page 54: ...54 SIP configuration NN47928 500 NN47928 500 ...
Page 80: ...80 QoS configuration NN47928 500 NN47928 500 ...
Page 82: ...82 Advanced configuration NN47928 500 NN47928 500 ...
Page 110: ...110 LAN advanced configuration NN47928 500 NN47928 500 ...
Page 144: ...144 IP routing advanced configuration NN47928 500 NN47928 500 ...
Page 152: ...152 DHCP advanced configuration NN47928 500 NN47928 500 ...
Page 164: ...164 QoS advanced configuration NN47928 500 NN47928 500 ...
Page 176: ...176 VPN advanced configuration NN47928 500 NN47928 500 ...
Page 200: ...200 Port management advanced configuration NN47928 500 NN47928 500 ...