Phase1 is de-encrypted. Without PFS, the key in Phase2 is created based on the key in Phase1 and thus once the key in Phase1 is de-encrypted, the key in Phase2 is easy to be de-encrypted, in this case, the communication secrecy is threatened.

SA Lifetime: Specify IPsec SA Lifetime for IKE mode.

Status:Activate or inactivate the entry.

zManual Mode

IPsec Proposal:

Select the IPsec Proposal. Only one proposal can be

 

 

selected on Manual mode. You need to first create the

 

 

IPsec Proposal.

Incoming SPI:

Specify the Incoming SPI (Security Parameter Index)

 

 

manually. The Incoming SPI here must match the

 

 

Outgoing SPI value at the other end of the tunnel, and

 

 

vice versa.

AH

Authentication

Specify the inbound AH Authentication Key manually if AH

Key-In:

protocol is used in the corresponding IPsec Proposal. The

 

 

inbound key here must match the outbound AH

 

 

authentication key at the other end of the tunnel, and vice

 

 

versa.

ESP

Authentication

Specify the inbound ESP Authentication Key manually if

Key-In:

ESP protocol is used in the corresponding IPsec

 

 

Proposal. The inbound key here must match the outbound

 

 

ESP authentication key at the other end of the tunnel, and

 

 

vice versa.

ESP

Encryption

Specify the inbound ESP Encryption Key manually if ESP

Key-In:

protocol is used in the corresponding IPsec Proposal. The

 

 

inbound key here must match the outbound ESP

 

 

encryption key at the other end of the tunnel, and vice

 

 

versa.

-92-

Page 97
Image 97
TP-Link TL-ER6120 manual Manual Mode, IPsec Proposal, Incoming SPI, Key-In, Encryption

TL-ER6120 specifications

The TP-Link TL-ER6120 is a robust and versatile gigabit router designed for small to medium-sized businesses, offering high-performance routing capabilities while ensuring secure network management. This device stands out for its user-friendly configuration, affordability, and rich feature set tailored for business needs.

One of the key features of the TL-ER6120 is its advanced routing capabilities. It supports load balancing and failover, ensuring reliable internet connectivity by distributing traffic across multiple WAN ports. This helps to maintain optimal performance even during high-traffic periods. The router can accommodate up to three WAN ports, providing flexibility in terms of connection options and redundancy.

Security is paramount in any business network, and the TL-ER6120 does not disappoint. It includes a robust firewall with stateful packet inspection, preventing unauthorized access and safeguarding sensitive data. The router also supports various VPN protocols, including PPTP, L2TP, and IPSec, enabling secure remote access for employees working from remote locations. This feature is particularly beneficial as remote work becomes more prevalent.

In addition to its security features, the TL-ER6120 offers support for VLAN configuration, allowing businesses to segment their networks for better performance and security. Dynamic Routing Protocols such as RIP v1/v2, and static routing are also supported, ensuring seamless data exchange across different network segments.

Another significant aspect of the TL-ER6120 is its Quality of Service (QoS) functionality. This feature enables users to prioritize bandwidth for critical applications, ensuring that services like VoIP and video conferencing maintain optimal performance. By managing the flow of data, businesses can enhance their operational efficiency.

The TL-ER6120 is equipped with several advanced management features, including a web-based user interface that simplifies network configuration and monitoring. Users can easily manage their network settings, view traffic statistics, and troubleshoot issues without advanced technical knowledge.

In conclusion, the TP-Link TL-ER6120 is an excellent choice for businesses seeking a reliable, feature-rich router. Its combination of security, performance, and ease of use makes it an ideal solution for managing business networks efficiently. Whether for load balancing, secure remote access, or network segmentation, the TL-ER6120 meets diverse business needs with sophistication and reliability.