
Prestige 652 ADSL Security Router
Table
FIELD | DESCRIPTION | EXAMPLE |
| Press [SPACE BAR] to choose from 3DES or DES and then press [ENTER]. |
|
|
|
|
Authentication | MD5 (Message Digest 5) and SHA1 (Secure Hash Algorithm) are hash | MD5 |
Algorithm | algorithms used to authenticate packet data. The SHA1 algorithm is |
|
| generally considered stronger than MD5, but is slightly slower. |
|
| Press [SPACE BAR] to choose from SHA1 or MD5 and then press [ENTER]. |
|
|
|
|
SA Life Time | Define the length of time before an IKE Security Association automatically | 28800 |
(Seconds) | renegotiates in this field. It may range from 60 to 3,000,000 seconds (almost | (default) |
| 35 days). |
|
| A short SA Life Time increases security by forcing the two VPN gateways to |
|
| update the encryption and authentication keys. However, every time the VPN |
|
| tunnel renegotiates, all users accessing remote resources are temporarily |
|
| disconnected. |
|
|
|
|
Key Group | You must choose a key group for phase 1 IKE setup. DH1 (default) refers to | DH1 |
|
| |
| Hellman Group 2 a 1024 bit (1Kb) random number. |
|
Phase 2 |
|
|
|
|
|
Active Protocol | Press [SPACE BAR] to choose from ESP or AH and then press [ENTER]. | ESP |
| See earlier for a discussion of these protocols. |
|
|
|
|
Encryption | Press [SPACE BAR] to choose from NULL, 3DES or DES and then press | DES |
Algorithm | [ENTER]. Select NULL to set up a tunnel without encryption. |
|
Authentication | Press [SPACE BAR] to choose from SHA1 or MD5 and then press [ENTER]. | SHA1 |
Algorithm |
|
|
SA Life Time | Define the length of time before an IKE Security Association automatically | 28800 |
(Seconds) | renegotiates in this field. It may range from 60 to 3,000,000 seconds (almost | (default) |
| 35 days). |
|
Encapsulation | Press [SPACE BAR] to choose from Tunnel mode or Transport mode and | Tunnel |
| then press [ENTER]. See earlier for a discussion of these. |
|
|
|
|
Perfect Forward | Perfect Forward Secrecy (PFS) is disabled (None) by default in phase 2 | None |
Secrecy (PFS) | IPSec SA setup. This allows faster IPSec setup, but is not so secure. Press |
|
| [SPACE BAR] and choose from DH1 or DH2 to enable PFS. DH1 refers to |
|
|
| |
| Hellman Group 2 a 1024 bit (1Kb) random number (more secure, yet slower). |
|
When you have completed this menu, press [ENTER] at the prompt “Press ENTER to Confirm…” to save your configuration, or press [ESC] at any time to cancel.
VPN/IPSec Setup |