D-Link DIR-455 manual PFS Group, Preshared Key, Remote ID, Local ID, XAuth None, XAuth Server Mode

Page 41

Section 3 - Configuration

PFS Group:

Three groups can be selected: None, Group 1, Group 2, Group 5.

 

None: No pfs group is used.

 

Group 1: Uses a 768-bit Diffie-Hellman prime modulus group.

 

Group 2: Uses a 1024-bit Diffie-Hellman prime modulus group.

 

Group 5: Uses a 1536-bit Diffie-Hellman prime modulus group.

Preshared Key:

The first key that supports IKE mechanism of both VPN gateway and VPN client host for negotiating further

 

security keys. The pre-shared key must be same on both VPN gateways and clients.

Remote ID:

The Type and the Value must be the same as the Type and the Value of the Local ID of the remote VPN

 

gateway.

Local ID:

The Type and the Value must be the same as the Type and the Value of the Remote ID of the remote VPN

 

gateway.

Extended Authentication:

With the xAuth feature, the VPN client (or initiator) needs to provide additional user information to remote VPN

 

server (or VPN gateway) for extended authentication. The VPN server would reject the connect request from

 

VPN clients because of the unknown user, even though the pre-shared key is correct. This function is suitable

 

to remote mobile VPN clients. You can configure a VPN rule with a pre-shared key for all remote users using,

 

but you can also designate only someone is permitted to establish VPN connection with VPN server.

xAuth - None:

Disables Extended Authentication (xAuth).

xAuth - Server Mode:

Select this checkbox if the device behaves as a VPN server, and will verify the legality of user information

 

from VPN client. The user information that is provided by VPN client needs to match to user information that

 

is in local user database of VPN server. You can press “XAUTH account” button to edit local user database.

 

Please note that only VPN clients with xAuth can establish VPN connection with the device if this checkbox

 

has been selected.

Set IKE Proposal:

Select this checkbox to enable IKE proposals.

Set IPSec Proposal:

Select this checkbox to enable IPSec proposals

 

 

D-Link DIR-455 User Manual

37

Image 41
Contents Page Trademarks PrefaceTable of Contents Troubleshooting Wireless Basics ProductPackageOverviewContents Introduction Hardware Overview PowerRear Panel LAN4 LAN3 LAN2 LAN1 WAN SIMWAN LAN1 LAN2 LAN3 LAN4 Front PanelWPS SMS WlanWAN LEDsConnect to Your Network InstallationConnect a Telephone Wireless Installation Considerations Web-based Configuration Utility ConfigurationInternet Connection Setup Wizard Setup WizardClick Internet Connection Setup Wizard to begin Manual Internet Connection Setup and skip toPage Page Page Click Manual Internet Connection Setup to begin Manual Internet Connection SetupInternet Connection Type Internet ConnectionDynamic IP Dhcp PPPoE Reconnect Mode Address ModePptp IP Address Pptp Subnet MaskL2TP Subnet Mask L2TP IP AddressKeep Alive AuthenticationDialed Number Static IP GRE Tunnel GRE SettingsTunnels Information Mode Wireless SettingsWireless Network Settings Wireless Security Mode Router Settings Network SettingsEnable Dhcp Server Dhcp Server SettingsDhcp Lease Time Secondary Wins IP AddressVPN Settings Page Encapsulation Protocol ESP, AH, or ESP+AH Tunnel 1 IKEPage Page Ipsec Proposal Settings IKE Proposal SettingsTunnel 1 Manual Key Page Encapsulation Protocol ESP, AH, or ESP+AH PFS Group XAuth Server ModePreshared Key Remote IDIKE Proposal Settings Create Message Message ServiceSMS Inbox Receiver CancelInbox RefreshVirtual Server EnableCopy to Virtual Servers ListApplication Rules Application RulesQOS Packet Filter QoS EngineLocal IP Ports QoS PriorityMAC Filtering Rules MAC Filtering SettingsMAC Address Filter URL Filtering Rules URL FilterOutbound Filter Rules List Outbound Filter SettingOutbound Filter Inbound Filter Rules List Intbound Filter SettingInbound Filter Set Community SnmpRouting Rules RIP SettingRouting Dtim Interval WMM Capable TX Rates Advanced WirelessWAN Ping Advanced NetworkUpnp Remote Management AdminAdministrator Time ConfigurationTime Zone Set the Time and DateSyslog Mail Settings System Firmware Username / E-mail Enter the Username for your Dynamic DNSSystem Check Schedules Device Information Logs Statistics Wireless Support What is WEP? Wireless SecurityNext to Security Mode, select Enable WEP Security Configure WEPWhat is WPA? Configure WPA-PSK Configure WPA Radius Using Windows Vista Connect to a Wireless NetworkConfigure Wireless Security Page Using Windows XP Configure WEP Page Configure WPA-PSK Page Why can’t I access the web-based configuration utility? TroubleshootingWhat can I do if I forgot my password? Wireless Basics Wireless Personal Area Network Wpan Wireless Local Area Network WlanSmall Office and Home Office HomeSecurity Centralize your Router or Access PointEliminate Interference Wireless Modes Check your IP address Networking BasicsStep Statically Assign an IP addressGSM Band GSM/GPRS/EDGE Technical SpecificationsDimensions L x W x H