Prestige 2602HW Series User’s Guide
Table 67 VPN: Manual Key (continued)
LABEL | DESCRIPTION |
|
|
End / Subnet Mask | When the Remote Address Type field is configured to Single, this field is N/A. |
| When the Remote Address Type field is configured to Range, enter the end |
| (static) IP address, in a range of computers on the network behind the remote |
| IPSec router. When the Remote Address Type field is configured to Subnet, |
| enter a subnet mask on the network behind the remote IPSec router. |
Address |
|
Information |
|
My IP Address | Enter the WAN IP address of your Prestige. The VPN tunnel has to be rebuilt if |
| this IP address changes. |
| The following applies if this field is configured as 0.0.0.0: |
| The Prestige uses the current Prestige WAN IP address (static or dynamic) to set |
| up the VPN tunnel. |
| If the WAN connection goes down, the Prestige uses the dial backup IP address |
| for the VPN tunnel when using dial backup or the LAN IP address when using |
| traffic redirect. See the chapter on WAN for details on dial backup and traffic |
| redirect. |
Secure Gateway | Type the WAN IP address or the URL (up to 31 characters) of the IPSec router |
Address | with which you're making the VPN connection. |
Security Protocol |
|
|
|
IPSec Protocol | Select ESP if you want to use ESP (Encapsulation Security Payload). The ESP |
| protocol (RFC 2406) provides encryption as well as some of the services offered |
| by AH. If you select ESP here, you must select options from the Encryption |
| Algorithm and Authentication Algorithm fields (described next). |
Encryption | Select DES, 3DES or NULL from the |
Algorithm | When DES is used for data communications, both sender and receiver must know |
| the same secret key, which can be used to encrypt and decrypt the message or to |
| generate and verify a message authentication code. The DES encryption |
| algorithm uses a |
| |
| processing power, resulting in increased latency and decreased throughput. |
| Select NULL to set up a tunnel without encryption. When you select NULL, you |
| do not enter an encryption key. |
Encapsulation Key | With DES, type a unique key 8 characters long. With 3DES, type a unique key 24 |
(only with ESP) | characters long. Any characters may be used, including spaces, but trailing |
| spaces are truncated. |
Authentication | Select SHA1 or MD5 from the |
Algorithm | SHA1 (Secure Hash Algorithm) are hash algorithms used to authenticate packet |
| data. The SHA1 algorithm is generally considered stronger than MD5, but is |
| slower. Select MD5 for minimal security and |
Authentication Key | Type a unique authentication key to be used by IPSec if applicable. Enter 16 |
| characters for MD5 authentication or 20 characters for |
| characters may be used, including spaces, but trailing spaces are truncated. |
Back | Click Back to return to the previous screen. |
|
|
Apply | Click Apply to save your changes back to the Prestige. |
|
|
Cancel | Click Cancel to begin configuring this screen afresh. |
|
|
Delete | Click Delete to remove the current rule. |
|
|
222 | Chapter 17 VPN Screens |