Linksys WAG54G manual Advanced VPN Tunnel Setup

Page 38

Wireless-G ADSL Gateway

When finished making your changes on this tab, click the Save Settings button to save these changes, or click the Cancel Changes button to undo your changes.

Advanced VPN Tunnel Setup

From the Advanced IPSec VPN Tunnel Setup screen you can adjust the settings for specific VPN tunnels.

Phase 1

Phase 1 is used to create a security association (SA), often called the IKE SA. After Phase 1 is completed, Phase 2 is used to create one or more IPSec SAs, which are then used to key IPSec sessions.

Operation Mode. There are two modes: Main and Aggressive, and they exchange the same IKE payloads in different sequences. Main mode is more common; however, some people prefer Aggressive mode because it is faster. Main mode is for normal usage and includes more authentication requirements than Aggressive mode. Main mode is recommended because it is more secure. No matter which mode is selected, the VPN Gateway will accept both Main and Aggressive requests from the remote VPN device.

Encryption. Select the length of the key used to encrypt/decrypt ESP packets. There are two choices: DES and 3DES. 3DES is recommended because it is more secure.

Authentication. Select the method used to authenticate ESP packets. There are two choices: MD5 and SHA. SHA is recommended because it is more secure.

Group. There are two Diffie-Hellman Groups to choose from: 768-bit and 1024-bit. Diffie-Hellman refers to a cryptographic technique that uses public and private keys for encryption and decryption.

Key Life Time. In the Key Lifetime field, you may optionally select to have the key expire at the end of a time period of your choosing. Enter the number of seconds you’d like the key to be used until a re-key negotiation between each endpoint is completed.

Phase 2

Encryption. The encryption method selected in Phase 1 will be displayed.

Authentication. The authentication method selected in Phase 1 will be displayed.

PFS. The status of PFS will be displayed.

Group. There are two Diffie-Hellman Groups to choose from: 768-bit and 1024-bit. Diffie-Hellman refers to a cryptographic technique that uses public and private keys for encryption and decryption.

Chapter 5: Configuring the Gateway

Figure 5-26: Advanced VPN Tunnel Setup

31

The Security Tab

Image 38
Contents Wireless- G Word definition How to Use this GuideCopyright and Trademarks Table of Contents Wireless-G Adsl Gateway Network Computer-to-VPN Gateway23 VPN Settings Summary Figure C-9 New Rule Properties Introduction WelcomeWhat’s in this Guide? Wireless-G Adsl Gateway IP Addresses Planning Your NetworkGateway’s Functions What’s an IP Address?Dynamic IP Addresses What is a VPN?Dhcp Dynamic Host Configuration Protocol Servers Why do I need a VPN? VPN Gateway to VPN GatewayMAC Address Spoofing Data SniffingGetting to Know the Wireless-G Adsl Gateway Back PanelWhile establishing the Adsl connection Front PanelIndication of any network activity InternetConnecting the Wireless-G Adsl Gateway OverviewWired Connection to a Computer Ethernet ConnectionWireless Connection to a Computer Wireless Configuring the GatewaySetup SecurityApplications & Gaming Access RestrictionsAdministration StatusInternet Setup How to Access the Web-based UtilitySetup Tab Multiplexing Select LLC or VC , depending on your ISPVirtual Circuit Enter the VPI and VCI ranges in the fields RFC 1483 Bridged Dynamic IPStatic IP RFC 1483 Routed RFC 2516 PPPoEBridged Mode Only RFC 2364 PPPoAOptional Settings Required by some ISPs Network SetupTZO.com Ddns TabDynDNS.org Advanced Routing Tab Advanced Routing13 Routing Table Wireless Network Wireless TabBasic Wireless Settings Tab Wireless Security Tab 15 WPA Pre-Shared Key17 WEP Wireless Access Tab Wireless Network AccessAdvanced Wireless Settings Tab Advanced WirelessAdditional Filters Security TabFirewall Local Security Gateway 22 VPNManual 24 Manual Key ManagementAdvanced VPN Tunnel Setup 26 Advanced VPN Tunnel SetupConfiguring the Gateway Security Tab Access Restrictions Tab Internet Access29 List of PCs Port Range Forwarding Applications and Gaming TabSingle Port Forwarding Port Triggering 33 Port TriggeringApplication-based QoS This setting allows you to specify traffic queue priorityAdvanced QoS Management Administration TabGateway Access Email Alerts ReportingUPnP Factory Defaults DiagnosticsBackup&Restore Ping TestUpgrade from LAN Firmware UpgradeReboot Gateway Information Status TabGateway Internet ConnectionsLocal Network 45 Local Network47 Wireless DSL Connection 49 DSL ConnectionNeed to set a static IP address on a computer Appendix a TroubleshootingCommon Problems and Solutions Want to test my Internet connection Wireless-G Adsl Gateway Wireless-G Adsl Gateway TCP UDP IP AddressCan’t get the Internet game, server, or application to work Firmware upgrade failed, and/or the Power LED is flashing To start over, I need to set the Gateway to factory defaultNeed to upgrade the firmware My DSL service’s PPPoE is always disconnectingPower LED flashes continuously Is IPSec Passthrough supported by the Gateway? Frequently Asked QuestionsWhere is the Gateway installed on the network? Does the Gateway support IPX or AppleTalk?Does the Gateway support ICQ send file? Will the Gateway function in a Macintosh environment? What is DMZ Hosting?What are the advanced features of the Gateway? Is the Gateway cross-platform compatible?What is ad-hoc mode? What is the Ieee 802.11g standard?What Ieee 802.11b and 802.11g features are supported? What is infrastructure mode?What is DSSS? What is FHSS? And what are their differences? What is the ISM band?What is Spread Spectrum? How do I reset the Gateway? What is WEP?What is a MAC Address? How do I resolve issues with signal loss?Appendix B Wireless Security Important Information for Wireless ProductsWireless-G Adsl Gateway Wireless-G Adsl Gateway Environment WAG54GBuild Filter Lists How to Establish a Secure IPSec TunnelCreate an IPSec Policy Filter List 1 win-RouterFilter List 2 Router -win Figure C-4 IP Filter LIstFigure C-7 IP Filter List Configure Individual Tunnel Rules Tunnel 1 win-RouterFigure C-13 Authentication Methods Figure C-16 Tunnel Setting Tab Tunnel 2 Router-winFigure C-19 IP Filter List Tab Figure C-22 Preshared Key Assign New IPSec Policy Figure C-25 Connection TypeCreate a Tunnel Through the Web-Based Utility Figure C-28 VPN TabFigure D-1 IP Configuration Screen Windows 98 or Me InstructionsWindows 2000 or XP Instructions Figure D-3 MAC Address/Physical AddressUpgrade from WAN Appendix E Upgrading FirmwareAppendix F Glossary Wireless-G Adsl Gateway Wireless-G Adsl Gateway Wireless-G Adsl Gateway Wireless-G Adsl Gateway Wireless-G Adsl Gateway Annex-B, WAG54G-DE UR-2 Appendix G SpecificationsStandards Operating Temp 0ºC to 40ºC10% to 85% Non-Condensing Storage Temp 20ºC to 70ºC Operating HumidityStorage Humidity Appendix H Regulatory Information FCC StatementWireless-G Adsl Gateway Radio EN 300 EMC EN 301 489-1, EN 301 Safety EN Belgium Applicable Power Levels in FranceLocation Frequency Range MHz Power Eirp Wireless-G Adsl Gateway Open the Wireless Network Connection window Appendix I Warranty Information Outside of Europe Mail Address Appendix J Contact InformationEurope Mail Address