D-Link DFL-600 Инструкция по эксплуатации онлайн [68/113] 17533

D-Link DFL-600 Инструкция по эксплуатации онлайн [68/113] 17533
Phase 2 Proposal
The following entries will establish the setup
for the negotiation between the two endpoints
for the encryption of messages once the VPN
tunnel has been initiated.
PFS Mode
This drop-down menu allows you to specify the
mode that will be used for IPSec Perfect
Forward Security (PFS). The choices are
Disabled, Group 1, and Group 2. Group 1
uses 768-bit encryption, and Group 2 uses
1024-bit encryption. You must use exactly the
same PFS encryption mode on both ends of the
VPN tunnel.
IPSec Operation
This drop-down menu allows you to select the
level of encryption that will be applied to
packets that are sent between the two endpoints
of a VPN tunnel.
ESP specifies that the entire packet will be
encrypted (by the DES or 3DES algorithm, as
selected below) and authenticated (by the MD5
or SHA algorithm, as selected below).
AH specifies that only the authentication
algorithm (MD5 or SHA, as selected below)
will be used. When AH is selected, the data
portion of packets sent between the two
endpoints of a VPN tunnel will not be
encrypted.
IPSec Life Duration
This is similar to the IKE Life Duration,
described above. It is the duration, in seconds,
of the phase 2 key, after the tunnel is
established. When this time has past, the two
peers will trigger the phase 2 negotiation to set
up a new phase 2 key and rebuild the tunnel.

Содержание

Скачать