Prestige 652H/HW Series User’s Guide
16-26
VPN
Screens
Table 16-9 VPN Manual Setup
LABEL
DESCRIPTION
IPSec Protocol Select
ESP
if you want to use ESP (Encapsulation Security Payload). The ESP
protocol (RFC 2406) provides encryption as well as some of the services offered by
AH
. If you select ESP here, you must select options from the
Encryption
Algorithm
and
Authentication Algorithm
fields (described next).
Encryption Algorithm Select
DES
,
3DES
or
NULL
from the drop-down list box.
When
DES
is used for data communications, both sender and receiver must know
the same secret key, which can be used to encrypt and decrypt the message or to
generate and verify a message authentication code. The
DES
encryption algorithm
uses a 56-bit key. Triple DES (
3DES
) is a variation on
DES
that uses a 168-bit key.
As a result,
3DES
is more secure than
DES
. It also requires more processing
power, resulting in increased latency and decreased throughput. Select
NULL
to set
up a tunnel without encryption. When you select
NULL
, you do not enter an
encryption key.
Encapsulation Key
(only with ESP)
With
DES
, type a unique key 8 characters long. With
3DES
, type a unique key 24
characters long. Any characters may be used, including spaces, but trailing spaces
are truncated.
Authentication
Algorithm
Select
SHA1
or
MD5
from the drop-down list box.
MD5
(Message Digest 5) and
SHA1
(Secure Hash Algorithm) are hash algorithms used to authenticate packet
data. The
SHA1
algorithm is generally considered stronger than
MD5
, but is slower.
Select
MD5
for minimal security and
SHA-1
for maximum security.
Authentication Key Type a unique authentication key to be used by IPSec if applicable. Enter 16
characters for
MD5
authentication or 20 characters for
SHA-1
authentication. Any
characters may be used, including spaces, but trailing spaces are truncated.
Back
Click
Back
to return to the previous screen.
Apply
Click
Apply
to save your changes back to the Prestige.
Cancel
Click
Cancel
to begin configuring this screen afresh.
Delete
Click
Delete
to remove the current rule.
16.15 Viewing SA Monitor
Click
VPN
and
Monitor
to open the
SA Monitor
screen as shown. Use this screen to display and manage
active VPN connections.
A Security Association (SA) is the group of security settings related to a specific VPN tunnel. This screen
displays active VPN connections. Use
Refresh
to display active VPN connections. This screen is read-only.
The following table describes the fields in this tab.
Summary of Contents for Prestige 652H series
Page 32: ......
Page 50: ......
Page 66: ......
Page 68: ......
Page 76: ......
Page 80: ......
Page 120: ...Prestige 652H HW Series User s Guide 8 12 WAN Setup Figure 8 6 Advanced WAN Backup ...
Page 128: ......
Page 146: ......
Page 148: ......
Page 162: ......
Page 178: ...Prestige 652H HW Series User s Guide 13 16 Firewall Screens Figure 13 8 Rule Edit Example ...
Page 196: ......
Page 198: ......
Page 204: ......
Page 214: ...Prestige 652H HW Series User s Guide 16 10 VPN Screens Figure 16 5 VPN IKE ...
Page 227: ...Prestige 652H HW Series User s Guide VPN Screens 16 23 Figure 16 8 Manual Setup ...
Page 238: ......
Page 258: ......
Page 277: ...Maintenance VIII Part VIII Maintenance This part covers the maintenance screens ...
Page 278: ......
Page 296: ......
Page 298: ......
Page 308: ......
Page 324: ......
Page 330: ......
Page 386: ......
Page 406: ......
Page 418: ......
Page 428: ......
Page 450: ......
Page 454: ......
Page 464: ......
Page 470: ......
Page 486: ......
Page 494: ......
Page 500: ......
Page 512: ......
Page 516: ......
Page 520: ......
Page 560: ......
Page 574: ......