D-Link DFL-1000 [95/168] Adding an encrypt policy

D-Link DFL-1000 [95/168] Adding an encrypt policy
DFL-1000 User Manual
9
5
Configuring the manual key VPN tunnel
Example manual key tunnel configuration shows the information required to configure the manual key
tunnel for the VPN in Example VPN between two internal networks
.
Example manual key tunnel configuration
Field name Main Office information Branch Office information
VPN Tunnel Name
Branch_Office_VPN Main_Office_VPN
Local SPI
100000 200000
Remote SPI
200000 100000
Remote Gateway
2.2.2.1 1.1.1.1
Replay Detection
Select Select
Encryption
Algorithm
ESP-3DES-HMAC-SHA1 ESP-3DES-HMAC-SHA1
Encryption Key
1234567890abcdef 1234567890abcdef
1234567890abcdef
1234567890abcdef 1234567890abcdef
1234567890abcdef
Authentication
Key
1234567890abcdef
1234567890abcdef12345678
1234567890abcdef
1234567890abcdef12345678
Concentrator
None None
The Local and Remote SPI values for both gateways should complement each other. You can use any HEX
characters for the Local and Remote SPI. The Local SPI on the Main Office gateway should match the Remote
SPI on the Branch Office gateway. The Remote SPI on the Main Office gateway should match the Local SPI
on the Branch Office gateway. Both the Local SPI and the Remote SPI values must be greater than BB8.
You can use any HEX characters for the encryption and authentication keys. However, they must be the same
on both VPN gateways.
For more information about manual key tunnel settings, see Adding a manual key VPN tunnel.
To configure the manual key tunnel on both VPN gateways:
Go to VPN > IPSEC > Manual Key .
Select New to add a manual key tunnel.
Configure the manual key tunnel using the Main Office information in Example manual key tunnel
configuration.
Select OK to save the manual key tunnel.
Repeat steps Select New to add a manual key tunnel.
to Select OK to save the manual key tunnel. on
the appropriate DFL-1000 NPG, using the Branch Office information in Example manual key tunnel
configuration.
Adding source and destination addresses
Use the procedure Adding source and destination addresses for a network-to-network VPN.
Adding an encrypt policy
Use the procedure Adding an encrypt policy for a network-to-network VPN.

Содержание

Скачать