D-Link DRO-210i manual Virtual Private Network

Page 49

Virtual Private Network

Virtual Private Network

VPN or virtual private networks allow multiple sites from an organization (and its clients, suppliers, etc.) to communicate securely over an insecure internet by encrypting all communication between the sites.

IPSec protocol is the Internet standard protocol for tunneling, encryption and authentication. IPSec can be used to protect the path between a pair of security gateways (Peer-To-Peer Mode) or between a security gateway and a host (IPSec Server Mode).

IPSec is designed to protect the network traffic by addressing basic issues like:

￿Access control: This is controlling the access to the remote host machines from the local hosts. This also involves local host access control, where the system administrators can control which local hosts can communicate to the remote hosts through the local IPSec gateways.

￿Data integrity: This makes sure that the data that is transferred from one IPSec gateway to another IPSec gateway is not tampered (changed).

￿Authentication of IPSec peers: This ensures that an IPSec peer is communicating with the proper remote IPSec peer. So it involves authenticating the remote IPSec peer.

￿Protection against replays: An intermediate person between any two communicating IPSec peers can spoof the packet, tamper it and then repeatedly send it to any of those IPSec gateways, thus causing Denial – of – Service attack. So IPSec has the capability to prevent this attack.

￿Traffic Confidentiality: This involves encrypting the data so that a third person cannot peek in through the data.

IPSec provides the securing services at IP layer, offering protection for IP and upper layer protocols. The security services are provided through the use of the following protocols

￿Cryptographic key management procedures and protocols, including the Internet Security Association and Key Management Protocol (ISAKMP) and the Internet Key Exchange protocol (IKE). In order to use IPSec, both the communicating peers need to have the same protocol, encryption algorithms and keys. IKE provides the mechanism for a pair of IPSec entities to negotiate security services and their associated session authentication and encryption keys.

￿Security protocols such as the Authentication Header (AH) and the Encapsulating Security Payload (ESP). The Authentication Header (AH) addresses data origin authentication, data integrity, and replay protection. The Encapsulating Security Payload (ESP) header has the same capabilities as AH in addition to data confidentiality and encryption. IPSec uses the AH by default. If data confidentiality is desired, ESP can be used, which has the additional encryption feature.

Dlink DRO-210i User Guide

49

Image 49
Contents DRO-210i Table Of Contents Virtual Private Network Bold About This ManualProduct Overview Product OverviewDlink DRO-210i User Guide Hardware Details DRO-210i Package ContentsFront Panel Rear Panel Routing Software FeaturesVPN Tools Optional Port Configuration Port ConfigurationDisabled WAN2/DMZ InterfacesLAN Interface LAN SettingsDMZ Interface Forgot LAN IP ?WAN Interface DMZ SettingsMaximum Transmission Unit Dynamic Mode Static ModeIP Settings for WAN1 Interface Dhcp Settings for WAN1 InterfaceUnnumbered Interfaces PPPoE ModePPPoE Settings for WAN1 Interface Dhcp DHCP, DNS and TimeDhcp Server DHCP, DNS and TimeDhcp Static Mapping Dhcp Static MappingDhcp Relay Dhcp RelayDNS Proxy DNS Proxy SettingsTime System Time SettingsRouting RoutingDynamic Routing Static RoutingStatic Routing RIP Settings Policy Based Routing Routing TableRouting Table Policy Based RoutingTo the same destination Backup Configuration Auto BackupHigh Availability High AvailabilityLoad Balancing Load Balancing ConfigurationEthernet Link Detection Ethernet WAN Link Detection NAT Interface Configuration NAT Interface ConfigurationNetwork Address Translation NATNAT Configuration NAT ConfigurationNAT Exception NAT Exception Virtual ServerVirtual Server/NAPT SIP-ALG SIP ALG ConfigurationNAT Session Table NAT TableFirewall Interface Configuration Interface ConfigurationFirewall Firewall PoliciesPolicy Rules Policy RulesInbound Policies Permitted Services Permitted ServicesInbound Policies Inbound PoliciesIP Permitted Rules Outbound PoliciesAdd Permitted IP Rule Outbound Policies Outbound PoliciesOutbound Policies Service Blocked Rule Blocked ServicesIP Blocked Rules Add Blocked IP RuleUntrusted Domain Domain FilterOutbound Policies Untrusted Domain Trusted DomainJava Filter Web FilterCookie Filter ActiveX FilterKeyword Exception Keyword FilterFile Extension Filter Blocking Log MAC FilterAdd Blocked MAC Address Blocking Log Table Intrusion Detection IDS ConfigurationIDS Configuration Black List Intrusion LogIntrusion Log Table Black List TableVirtual Private Network Virtual Private NetworkPeer-To-Peer IPSec Tunnel or PassthroughIPSec Passthrough IPSec TunnelVirtual Private Network Same IKE Encryption algorithm on both ends of a VPN tunnel IPSec Server IPSec Server ConfigurationsMaximum life duration is 86400 seconds Tunnel Table Tunnel Remote ID ConfigurationLimitation IPSec Status IPSec StatusIPSec Log Table IPSec LogClass Configuration Quality of ServiceQuality of Service HTB QoS ConfigurationsQuality of Service QoS Filter Configurations Filter ConfigurationTOS/DiffServ Type Of Service/DiffServQuality of Service Administration AdministrationDevice Information Device InfoSession Log Traffic StatisticsTraffic Statistics SysLog Password ChangeSession Log System LogPassword Recovery Change PasswordSystem SystemUpload/Download Update Firmware/ConfigurationRemote Access Remote AccessPing Test Ping TestAdministration Dlink DRO-210i User Guide Frequently Asked Questions Frequently Asked QuestionsGeneral DHCP, DNS Q6. What is the purpose of Dhcp Server Auto Configuration?High Availability RoutingFirewall Frequently Asked Questions 11.6 NAT 11.7 VPN Q21. What are the call features supported by SIP-ALG?11.8 QoS Frequently Asked Questions