CONEL UR5i v2 — настройка IPsec через веб-браузер: основные параметры и алгоритмы [61/106]

Превью страниц Страница 61 / 106
CONEL ER75i v2 [61/106] Configuration over web browser
1. CONFIGURATION OVER WEB BROWSER
Continued from previous page
Item Description
Encapsulation Mode IPsec mode (according to the method of encapsulation) You
can choose tunnel (entire IP datagram is encapsulated) or trans-
port (only IP header).
NAT traversal If address translation is used between two end points of the tun-
nel, it needs to enable NAT Traversal.
IKE Mode Defines mode for establishing connection (main or aggressive).
If the aggressive mode is selected, establishing of IPsec tunnel
will be faster, but encryption will set permanently on 3DES-MD5.
IKE Algorithm Way of algorithm selection:
auto encryption and hash alg. are selected automatically
manual encryption and hash alg. are defined by the user
IKE Encryption Encryption algorithm 3DES, AES128, AES192, AES256
IKE Hash Hash algorithm MD5 nebo SHA1
IKE DH Group Dif fie-Hellman groups determine the strength of the key used in
the key exchange process. Higher group numbers are more se-
cure, but require additional time to compute the key. Group with
higher number provides more security, but requires more pro-
cessing time.
ESP Algorithm Way of algorithm selection:
auto encryption and hash alg. are selected automatically
manual encryption and hash alg. are defined by the user
ESP Encryption Encryption algorithm DES, 3DES, AES128, AES192, AES256
ESP Hash Hash algorithm MD5 nebo SHA1
PFS Ensures that derived session keys are not compromised if one of
the pr ivate keys is compromised in the future
PFS DH Group Dif fie-Hellman group number (see IKE DH Group)
Key Lifetime Lifetime key data part of tunnel. The minimum value of this pa-
rameter is 60 s. The maximum value is 86400 s.
IKE Lifetime Lifetime key service part of tunnel. The minimum value of this
parameter is 60 s. The maximum value is 86400 s.
Rekey Margin Specifies how long before connection expiry should attempt to
negotiate a replacement begin. Maximum value must be less
than half of IKE and Key Lifetime parameters.
Continued on next page
53

Содержание

198

Узнайте о ключевых параметрах настройки IPsec через веб-браузер, включая режимы инкапсуляции, алгоритмы шифрования и управления ключами для безопасного соединения.

Кешбек Менеджер