ZyWALL 2 Series User’s Guide
Table
FIELD | DESCRIPTION | EXAMPLE |
|
|
|
Encryption | When DES is used for data communications, both sender and receiver must | DES |
Algorithm | know the same secret key, which can be used to encrypt and decrypt the |
|
| message or to generate and verify a message authentication code. ZyWALL |
|
| DES encryption algorithm uses a |
|
| Triple DES (3DES), is a variation on DES that uses a |
|
| 3DES is more secure than DES. It also requires more processing power, |
|
| resulting in slightly increased latency and decreased throughput. |
|
| This implementation of AES uses a |
|
| Press [SPACE BAR] to choose from DES, 3DES or AES and then press |
|
| [ENTER]. |
|
Authentication | MD5 (Message Digest 5) and SHA1 (Secure Hash Algorithm) are hash | SHA1 |
Algorithm | algorithms used to authenticate packet data. The SHA1 algorithm is generally |
|
| considered stronger than MD5, but is slightly slower. |
|
| Press [SPACE BAR] to choose from SHA1 or MD5 and then press [ENTER]. |
|
|
|
|
SA Life Time | Define the length of time before an IKE Security Association automatically | 28800 |
(Seconds) | renegotiates in this field. It may range from 180 to 3,000,000 seconds (almost | (default) |
| 35 days). |
|
| A short SA Life Time increases security by forcing the two VPN gateways to |
|
| update the encryption and authentication keys. However, every time the VPN |
|
| tunnel renegotiates, all users accessing remote resources are temporarily |
|
| disconnected. |
|
Key Group | You must choose a key group for phase 1 IKE setup. DH1 (default) refers to | DH1 |
|
| |
| Group 2 a 1024 bit (1Kb) random number. |
|
Phase 2 |
|
|
|
|
|
Active Protocol | Press [SPACE BAR] to choose from ESP or AH and then press [ENTER]. See | ESP |
| earlier for a discussion of these protocols. |
|
Encryption | Press [SPACE BAR] to choose from NULL, DES, 3DES or AES and then | DES |
Algorithm | press [ENTER]. Select NULL to set up a tunnel without encryption. |
|
Authentication | Press [SPACE BAR] to choose from SHA1 or MD5 and then press [ENTER]. | MD5 |
Algorithm |
|
|
|
|
|
SA Life Time | Define the length of time before an IPSec Security Association automatically | 28800 |
(Seconds) | renegotiates in this field. It may range from 180 to 3,000,000 seconds (almost | (default) |
| 35 days). |
|
|
|
|
VPN/IPSec Setup |