TRENDnet TW100-BRV204 IKE SA Life Time, DH Group, Ike Pfs, VPN Wizard - IKE Phase, IPSec PFS

Models: VPN Firewall Router TW100-BRV204

1 123
Download 123 pages 41.73 Kb
Page 82
Image 82
IKE SA Life Time

 

VPN

 

 

IKE SA Life Time

This setting does not have to match the remote VPN endpoint; the

 

shorter time will be used. Although measured in seconds, it is com-

 

mon to use time periods of several hours, such 28,800 seconds.

 

 

DH Group

Select the desired method, and ensure the remote VPN endpoint uses

 

the same method. The smaller bit size is slightly faster.

 

 

IKE PFS

If enabled, PFS (Perfect Forward Security) enhances security by

 

changing the IPsec key at regular intervals, and ensuring that each

 

key has no relationship to the previous key. Thus, breaking 1 key

 

will not assist in breaking the next key.

 

This setting should match the remote endpoint.

 

 

Click Next to see the following IKE Phase 2 screen.

 

Figure 53: VPN Wizard - IKE Phase 2

 

 

IKE Phase 2 (IPsec SA)

IPsec SA Life Time

This setting does not have to match the remote VPN endpoint; the

 

shorter time will be used. Although measured in seconds, it is

 

common to use time periods of several hours, such 28,800 seconds.

 

 

IPSec PFS

If enabled, PFS (Perfect Forward Security) enhances security by

 

changing the IPsec key at regular intervals, and ensuring that each

 

key has no relationship to the previous key. Thus, breaking 1 key

 

will not assist in breaking the next key.

 

 

AH Authentication

AH (Authentication Header) specifies the authentication protocol

 

for the VPN header, if used.

 

AH is often NOT used. If you do enable it, ensure the algorithm

 

selected matches the other VPN endpoint.

 

 

79

Page 82
Image 82
TRENDnet TW100-BRV204 manual IKE SA Life Time, DH Group, Ike Pfs, VPN Wizard - IKE Phase, IKE Phase 2 IPsec SA, IPSec PFS