USR-G808 User Manual
Technical Support:
Jinan USR IOT Technology Limited
www.usriot.com
39
1. DPD enable: enable this function or not,
√
means enable
2. DPD delay: setting connection testing interval
3. DPD timeout: setting connection testing timeout.
4. DPD action: setting connection testing operating
5. IKE algorithm: the first step including IKE encryption way, completely solution and DH exchange arithmetic
6. IKE life cycle: setting the IKE life cycle, the unit is second, default is 28800
7. SA type:in the second step can choose the ESP and AH.
8. ESP algorithm:choose the correspond way to encryption and complete solution
9. ESP life time: setting ESP life cycle, unit is S, default is:3600
10. Mode:negotiation mode default is main mode, can choose the aggr mode
11. Session key forward encryption(PFS): enable PFS if
√
12. Auth by
:
current support enjoy the key to certification.
Note:
Configuring successful, mark it in the ISAKMP SA established of the connection log; which is mean you have
succeed to build.
3.2.12.4. OPENVPN Client
OPENVPN is based on Openssl library. It supports bidirectional authentication based on certificate, that’s to say
Client needs to certificate Server and Server needs to certificate Client.
User can add a OPENVPN interface and configure it by Web Server as follow. Protocol can choose TUN(route mode)
or TAP(bridge mode).