High (ESP-Encapsulating Security Payload)- means

 

payload (data) will be encrypted and authenticated. Select

 

from below:

 

DES without Authentication -Use DES encryption algorithm

 

and not apply any authentication scheme.

 

DES with Authentication-Use DES encryption algorithm and

 

apply MD5 or SHA-1 authentication algorithm.

 

3DES without Authentication-Use triple DES encryption

 

algorithm and not apply any authentication scheme.

 

3DES with Authentication-Use triple DES encryption

 

algorithm and apply MD5 or SHA-1 authentication algorithm.

 

AES without Authentication-Use AES encryption algorithm

 

and not apply any authentication scheme.

 

AES with Authentication-Use AES encryption algorithm and

 

apply MD5 or SHA-1 authentication algorithm.

Advanced

Specify mode, proposal and key life of each IKE phase,

 

Gateway etc.

 

The window of advance setup is shown as below:

IKE phase 1 mode -Select from Main mode and Aggressive mode. The ultimate outcome is to exchange security proposals to create a protected secure channel. Main mode is more secure than Aggressive mode since more exchanges are done in a secure channel to set up the IPSec session. However, the Aggressive mode is faster. The default value in Vigor router is Main mode.

IKE phase 1 proposal-To propose the local available authentication schemes and encryption algorithms to the VPN peers, and get its feedback to find a match. Two combinations are available for Aggressive mode and nine for Main mode. We suggest you select the combination that covers the most schemes.

IKE phase 2 proposal-To propose the local available algorithms to the VPN peers, and get its feedback to find a match. Three combinations are available for both modes. We suggest you select the combination that covers the most algorithms.

IKE phase 1 key lifetime-For security reason, the lifetime of key should be defined. The default value is 28800 seconds. You may specify a value in between 900 and 86400 seconds. IKE phase 2 key lifetime-For security reason, the lifetime of key should be defined. The default value is 3600 seconds. You may specify a value in between 600 and 86400 seconds.

86

Vigor2800 Series User’s Guide

Page 90
Image 90
Draytek 2800 Series High ESP-Encapsulating Security Payload- means, 3DES without Authentication -Use triple DES encryption

2800 Series specifications

The Draytek 2800 series is a robust solution in the realm of networking, catering primarily to small and medium-sized enterprises (SMEs). This series provides essential features for those looking to establish reliable and secure connectivity. With its advanced technology, it positions itself as an excellent choice for businesses needing to manage their network capabilities efficiently.

One of the standout features of the Draytek 2800 series is its support for various WAN connections. Businesses can opt for ADSL, ADSL2+, or Ethernet connections, allowing them flexibility depending on their internet service capabilities. This versatility ensures that users can select the most appropriate setup based on the local infrastructure.

In terms of security, the Draytek 2800 series is equipped with robust firewalls, including stateful packet inspection and DoS protection. This ensures that the network remains protected from potential threats. Additionally, it offers VPN capabilities, enabling secure remote access for employees working from different locations. The support for multiple VPN protocols, such as PPTP and L2TP, allows for secure and versatile connections.

The series also features an integrated, 4-port Ethernet switch, simplifying the task of connecting multiple devices within a local area network. This encourages seamless communication and data sharing among connected devices. Furthermore, the Draytek 2800 series supports Quality of Service (QoS) capabilities, which allows businesses to prioritize bandwidth for critical applications, ensuring that high-demand services such as VoIP and video conferencing operate smoothly without interruptions.

Another characteristic is its web-based management interface, which simplifies network administration. IT professionals can easily configure and monitor the router settings without needing extensive technical expertise. The series also supports dynamic DNS, which is crucial for businesses that require consistent access to their networks through domain names rather than constantly changing IP addresses.

Additionally, the Draytek 2800 series is designed for scalability, allowing businesses to expand their network as needed without significant overhauls. This flexibility ensures that the system can grow alongside the business.

In summary, the Draytek 2800 series combines advanced features, reliable performance, and enhanced security, making it a preferred choice for SMEs looking to build a solid networking foundation. Its flexibility, security features, and user-friendly management tools provide a comprehensive networking solution that meets the needs of modern businesses.