ZyXEL Communications 792H manual Tunnel, ESP DES MD5

Models: 792H

1 428
Download 428 pages 12.67 Kb
Page 389
Image 389

Prestige 792H G.SHDSL Router

Table 36-1 Menu 27.1 IPSec Summary

FIELD

DESCRIPTION

EXAMPLE

 

 

 

Name

This field displays the unique identification name for this VPN rule. The

Taiwan

 

name may be up to 32 characters long but only 10 characters will be

 

 

displayed here.

 

 

 

 

A

Y signifies that this VPN rule is active.

Y

 

 

 

Local Addr

When the Addr Type field in Menu 27.1.1 IPSec Setup is configured to

192.168.1.35

Start

Single, this is a static IP address on the LAN behind your Prestige.

 

 

When the Addr Type field in Menu 27.1.1 IPSec Setup is configured to

 

 

Range, this is the beginning (static) IP address, in a range of computers

 

 

on the LAN behind your Prestige.

 

 

When the Addr Type field in Menu 27.1.1 IPSec Setup is configured to

 

 

SUBNET, this is a static IP address on the LAN behind your Prestige.

 

Addr End /

When the Addr Type field in Menu 27.1.1 IPSec Setup is configured to

192.168.1.38

Mask

Single, this is the same (static) IP address as in the Local Addr Start

 

 

field.

 

 

When the Addr Type field in Menu 27.1.1 IPSec Setup is configured to

 

 

Range, this is the end (static) IP address, in a range of computers on the

 

 

LAN behind your Prestige.

 

 

When the Addr Type field in Menu 27.1.1 IPSec Setup is configured to

 

 

SUBNET, this is a subnet mask on the LAN behind your Prestige.

 

Encap

This field displays Tunnel mode or Transport mode. See earlier for a

Tunnel

 

discussion of these. You need to finish configuring the VPN policy in menu

 

 

27.1.1.1 or 27.1.1.2 if ??? is displayed.

 

IPSec

This field displays the security protocols used for an SA. ESP provides

ESP DES MD5

Algorithm

confidentiality and integrity of data by encrypting the data and

 

 

encapsulating it into IP packets. Encryption methods include 56-bit DES

 

 

and 168-bit 3DES. NULL denotes a tunnel without encryption.

 

 

AH (Authentication Header) provides strong integrity and authentication

 

 

by adding authentication information to IP packets. This authentication

 

 

information is calculated using header and payload data in the IP packet.

 

 

This provides an additional level of security. AH choices are MD5 (default

 

 

- 128 bits) and SHA -1(160 bits).

 

 

Both AH and ESP increase the Prestige’s processing requirements and

 

 

communications latency (delay).

 

 

You need to finish configuring the VPN policy in menu 27.1.1.1 or 27.1.1.2

 

 

if ??? is displayed.

 

VPN/IPSec Setup

36-3

Page 389
Image 389
ZyXEL Communications 792H manual Tunnel, ESP DES MD5