Moxa WDR-3124A-EU-T [58/94] Wdr 3124a web console configuration

Moxa WDR-3124A-EU-T [58/94] Wdr 3124a web console configuration
WDR-3124A Web Console Configuration
3-35
Field Description Factory Default
Local ID Enter an ID (IP/FQDN/User_FQDN) to
identify and authenticate
the local VPN gateway.
Remote network Enter the remote VPN server subnet IP of the remote network.
Remote netmask Enter the remote VPN server subnet netmask of the remote
network.
Remote ID Enter an ID (IP/FQDN/User_FQDN
) to identify and authenticate
the remote VPN endpoint.
Key Exchange (Phase1)
Operation mode Select main mode or aggressive mode to configure the
standard negotiation parameters for IKE Phase 1 of the VPN
Tunnel.
Main
Authentication mode Select Pre-shared key, RSA Signature or X.509
authentication mode to for phase 1 key exchange.
The configuration fields vary depending on the authentication
mode you select. For information on configuring each
authentication mode, refer to the following sections.
Pre-shared key
Encryption algorithm Select the DES, 3DES, AES128, AES192 or AES256 of the
VPN
ISAKMP phase 1 encryption mode.
DES
Hash algorithm Select the MD5 or SHA-1 VPN key exchange phase 1 hash
mode.
MD5
DH group Select the DH-2(1024) or DH-5(1536) VPN key exchange
phase 1 Diffie-Hellman group. As the Diffie-Hellman Group
number increases, the higher the level of encryption
implemented for PFS.
DH-2
Negotiation time The number of allowed reconnect times when startup mode is
initiated. If the number is 0, this tunnel will always try
connecting to the remote gateway when the VPN tunnel is not
created successfully.
0
IKE life time Enter the number of minutes for the VPN IKE SA phase 1
Lifetime. This is the period of time to pass before establishing a
new IPSec security association (SA) with the remote endpoint.
60
Rekey expire time Enter the number of minutes for the
Start to Rekey before IKE
lifetime expired.
9
Rekey fuzz percent The rekey expire time will change randomly to enhance the
security. Rekey fuzz percent is the maximum random change
margin of the Rekey expire time. 100% means the rekey expire
time will not change randomly.
100%
Data Exchange (phase2)
Perfect forward secrecy
Enable or disable the Perfect Forward Secrecy. PFS is an
additional security protocol.
Disable
SA life time Enter the number of seconds for the VPN ISAKMP phase 2
Lifetime. This is the period of time to pass before establishing a
new IPSec security association (SA) with the remote endpoint.
480
Encryption algorithm Select the DES, 3DES, AES128, AES192 or AES256 of the
VPN
ISAKMP phase 1 encryption mode.
DES
Hash algorithm Select the MD5 or SHA-1 VPN ISAKMP phase 1 authentication
mode.
MD5
Dead Peer Detection
DPD action When you enable the Dead Peer Detection (DPD) feature, the
WDR-3124A performs one of the following actions when
connection to a remote IPSec tunnel is down:
Hold: Keep the VPN tunnel
Clear: Clear the VPN tunnel
Disable

Содержание

Скачать