D-Link DFL-600 [66/113] Add new tunnel

D-Link DFL-600 [66/113] Add new tunnel
Add/New Tunnel
The following fields will identify the VPN
tunnel on the DFL-600.
Tunnel ID
An alphanumeric string that identifies the
remote tunnel. A sting of up to 63 characters
can be entered. The Tunnel ID is sometimes
called the Negotiation ID of the remote
gateway.
Termination IP
The IP address of the remote gateway.
Shared Key
The encryption key that should be entered
exactly the same way on both endpoints in
order to establish Phase 1 negotiation.
Tunnel Type
This drop-down menu allows you to select the
type of VPN Tunnel you are configuring. You
can choose between Public, Private, and
Manual. At the time of the writing of this
manual, only Public IPSec VPN tunnels are
supported.
Phase 1 Proposal
Phase 1 VPN IPSec negotiation allows the two
endpoints of a VPN tunnel to communicate in a
secure way so that the encryption for the actual
VPN tunnel can be accomplished in the Phase 2
negotiation. The following fields will define
the way the encryption and decryption of the
Phase 1 negotiation is handled.
Mode
You can select between Main and Aggressive
modes for the Phase 1 negotiation to establish a
VPN IPSec tunnel. In the Main mode, all
communication between the two endpoints of
an IPSec VPN tunnel are encrypted. In
Aggressive mode, there is no encryption in the
Phase 1 negotiation.
DH Group
The DH algorithm allows the DFL-600 to
generate secret keys for encryption for the
Phase 1 negotiation. Group 1 generates a 768-
bit key and Group 2 generates a 1024-bit key.
The same DH Group must be used on both ends
of an IPSec VPN tunnel.

Содержание

Скачать