D-Link DFL-1000 [72/168] Select ok to save the remote gateway

D-Link DFL-1000 [72/168] Select ok to save the remote gateway
DFL-1000 User Manual
7
2
Gateway Name
Enter a name for the gateway. The name can contain numbers (0-9), uppercase and lowercase
letters (A-Z, a-z), and the special characters - and _. Other special characters and spaces are
not allowed.
Remote Gateway
Select Static IP Address or Dialup User.
IP Address
If you select Static IP Address, the IP Address field appears. Enter the IP address of the remote
IPSec VPN gateway or client that can connect to the DFL-1000 NPG.
User Group
If you select Dialup User, the User Group field appears. For authentication purposes, you can
select the group of users that will have access to the remote gateway. For information about
dialup VPN authentication, see About dialup VPN authentication
.
Mode
Select Aggressive or Main (ID Protection) mode. Both modes establish a secure channel. Main
mode offers greater security because identifying information is exchanged after encryption is set
up. Aggressive mode is less secure because it exchanges identifying information before
encryption is set up.
For both Static IP Address and Dialup User remote gateways, the mode at both ends of the
gateway must be the same.
P1 Proposal
Select up to three encryption and authentication algorithm combinations to propose for phase 1.
Two are selected by default. To decrease the number of combinations selected, select the
minus sign. To increase the number of combinations selected, select the plus sign. See About
the P1 proposal.
DH Group
Select one or more Diffie-Hellman groups to propose for Phase 1 of the IPSec VPN connection.
You can select DH group 1, 2, and 5. See About DH groups
.
Keylife
Specify the keylife for Phase 1. The keylife is the amount of time in seconds before the phase 1
encryption key expires. When the key expires, a new key is generated without interrupting
service. P1 proposal keylife can be from 120 to 172,800 seconds.
Authentication
(Pre-shared Key)
Enter an authentication key. The key can contain any characters and must be at least 6
characters in length. The pre-shared key must be the same on the server and on the remote
VPN gateway or client and should only be known by network administrators. For information
about the pre-shared key, see About dialup VPN authentication
.
Local ID
Optionally enter a local ID if you set Remote Gateway to Dialup user and select Aggressive
Mode. Enter the IP address of the dialup user or the domain name of the dialup user (for
example, domain.com). If you do not add a local ID, the DFL-1000 external interface
automatically becomes the Local ID. For information about authentication and the Local ID, see
About dialup VPN authentication
.
Nat-traversal
Select Enable if you expect the IPSec VPN traffic to go through a gateway that performs NAT. If
no NAT device is detected, enabling NAT traversal will have no effect. Both ends of the gateway
must have the same NAT traversal setting. See About NAT traversal
.
Keepalive
Frequency
If you enable NAT-traversal, you can change the number of seconds in the Keepalive Frequency
field. This number specifies, in seconds, how frequently empty UDP packets are sent through
the NAT device to ensure that the NAT mapping does not change until P1 and P2 keylife
expires. The keepalive frequency can be from 0 to 900 seconds.
Select OK to save the remote gateway.

Содержание

Скачать