Prestige 792H G.SHDSL Router

36.4 IKE Setup

To edit this menu, the Key Management field in Menu 27.1.1 – IPSec Setup must be set to IKE. Move the cursor to the Edit Key Management Setup field in Menu 27.1.1 – IPSec Setup; press [SPACE BAR] to select Yes and then press [ENTER] to display Menu 27.1.1.1 – IKE Setup.

Menu 27.1.1.1 - IKE Setup

Phase 1

Negotiation Mode= Main

PSK= 123456789

Encryption Algorithm= DES

Authentication Algorithm= SHA1

SA Life Time (Seconds)= 28800

Key Group= DH1

Phase 2

Active Protocol = ESP

Encryption Algorithm = DES

Authentication Algorithm = SHA1

SA Life Time (Seconds)= 28800

Encapsulation = Tunnel

Perfect Forward Secrecy (PFS)= None

Press ENTER to Confirm or ESC to Cancel:

Figure 36-5Menu 27.1.1.1 IKE Setup

The following table describes the fields in this menu.

FIELD

Table 36-3Menu 27.1.1.1 IKE Setup

DESCRIPTION

EXAMPLE

 

 

Phase 1

Negotiation

Press [SPACE BAR] to choose from Main or Aggressive and then press

Main

Mode

[ENTER]. See earlier for a discussion of these modes. Multiple SAs

 

 

connecting through a secure gateway must have the same negotiation mode.

 

PSK (Pre-

Prestige gateways authenticate an IKE VPN session by matching pre-shared

 

Shared Key)

keys. Pre-shared keys are best for small networks with fewer than ten nodes.

 

 

Enter your pre-shared key here. Enter up to 31 characters. Any character may

 

 

be used, including spaces, but trailing spaces are truncated.

 

 

Both ends of the VPN tunnel must use the same pre-shared key. You will

 

 

receive a “PYLD_MALFORMED” (payload malformed) packet if the same pre-

 

 

shared key is not used on both ends.

 

 

 

 

VPN/IPSec Setup

36-11

Page 397
Image 397
ZyXEL Communications 792H manual Field, 3Menu 27.1.1.1 IKE Setup, Description Example, Main