Sierra Wireless AirLink MP Guía de usuario Pagina 66

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 237
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 65
ALEOS User Guide
60 20080616
My Identity If these fields are left blank, My Identity will default to the WAN IP address assigned by the
carrier and Peer Identity will default to the VPN Server IP. For a fully qualified domain name
(FQDN), these values should be preceded by an ‘@’character (@www.domain.com). For
user-FQDN, these values should include a username (user@domain.com)
Peer Identity Required in some configurations to identify the client or peer side of a VPN connection.
This defaults to the VPN server IP address.
Negotiation Mode Main Mode or Aggressive. To operate the onboard VPN under Aggressive mode, enable
this configuration. By default the AirLink Device operates under Main Mode. Aggressive
mode offers increased performance at the expense of security.
IKE Encryption
Algorithm
DES, 3DES, or AES. Determines the type and length of encryption key used to encrypt/
decrypt ESP (Encapsulating Security Payload) packets. 3DES supports 168-bit encryption.
AES (Advanced Encryption Standard) is supports 128 bit encryption.
IKE Authentication
Algorithm
SHA1 or MD5. Can be configured with MD5 or SHA1. MD5 is an algorithm that produces a
128-bit digest for authentication. SHA1 is a more secure algorithm that produces a 160-bit
digest.
IPSec Encryption
Algorithm
DES, 3DES, or AES. Determines the type and length of encryption key used to encrypt/
decrypt ESP (Encapsulating Security Payload) packets. 3DES supports 168-bit encryption.
AES (Advanced Encryption Standard) supports 128 bit encryption.
IPSec Authentication
Algorithm
SHA1 or MD5. Can be configured with MD5 or SHA1. MD5 is an algorithm that produces a
128-bit digest for authentication. SHA1 is a more secure algorithm that produces a 160-bit
digest.
IKE SA Life Time 180 to 86400. Determines how long the VPN tunnel is active in seconds. The default value
is 28,800 seconds, or 8 hours.
Local Address Type The network information of the device.
Local Address Device’s subnet address.
Local Address -
Netmask
24 bits netmask.
Remote Address Type The network information of the IPSec server behind the IPSec gateway.
Remote Address The IP address of the device behind the gateway.
Remote Address -
Netmask
24 bits netmask.
Perfect Forward
Secrecy
Yes or No. Provides additional security through a DH shared secret value. When this
feature is enabled, one key cannot be derived from another. This ensures previous and
subsequent encryption keys are secure even if one key is compromised.
IPSec Key Group DH1, DH2, or DH5. Determines how the AirLink Device VPN creates an SA with the VPN
server. The DH (Diffie-Hellman) key exchange protocol establishes pre-shared keysd uring
the phase 1 authentication. AirLink Device supports three prime key lengths,including
Group 1 (768 bits), Group 2 (1,024 bits), and Group 5 (1,536 bits).
IPSec SA Life Time 180 to 86400. Determines how long the VPN tunnel is active in seconds. The default value
is 28,800 seconds, or 8 hours.
Keep Tunnel Alive This implies that the tunnel needs to be established automatically and if it the tunnel is
pulled down, it needs to be restablished automatically.
Command Description
Vista de pagina 65
1 2 ... 61 62 63 64 65 66 67 68 69 70 71 ... 236 237

Comentarios a estos manuales

Sin comentarios