Avaya Business Secure Router 222 Configuration - Basics Manual de usuario Pagina 242

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 451
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 241
242 Chapter 13 VPN
NN47922-500
Table 59 describes the fields in Figure 76.
Table 59 VPN Branch Office Advanced Rule Setup
Label Description
Enable Replay
Detection
As a VPN setup is processing intensive, the system is vulnerable to
Denial of Service (DoS) attacks. The IPSec receiver can detect and
reject old or duplicate packets to protect against replay attacks.
Enable replay detection by setting this field to YES.
Phase 1 A phase 1 exchange establishes an IKE SA (Security Association).
Multiple Proposal Select this check box to allow the Business Secure Router to use any
of its phase 1 encryption and authentication algorithms when
negotiating an IKE SA.
Clear this check box to have the Business Secure Router use only the
phase 1 encryption and authentication algorithms configured below
when negotiating an IKE SA.
Negotiation Mode Select Main for identity protection. Select Aggressive to allow more
incoming connections from dynamic IP addresses to use separate
passwords. The Business Secure Router's negotiation mode must be
identical to that on the remote VPN switch. Multiple SAs connecting
through a VPN switch must have the same negotiation mode.
Encryption
Algorithm
Select DES, 3DES or AES from the drop-down list.
When you use one of these encryption algorithms for data
communications, both the sending device and the receiving device
must use the same secret key, which can be used to encrypt and
decrypt the message or to generate and verify a message
authentication code. The DES encryption algorithm uses a 56-bit key.
Triple DES (3DES) is a variation on DES that uses a 168-bit key. As a
result, 3DES is more secure than DES. It also requires more
processing power, resulting in increased latency and decreased
throughput. You can select a 128-bit, 192-bit, or 256-bit key with this
implementation of AES. AES is faster than 3DES.
Authentication
Algorithm
Select SHA1 or MD5 from the drop-down list. The Business Secure
Router's authentication algorithm must be identical to the remote VPN
switch. MD5 (Message Digest 5) and SHA1 (Secure Hash Algorithm)
are hash algorithms used to authenticate the source and integrity of
packet data. The SHA1 algorithm is generally considered stronger
than MD5, but is slower. Select SHA-1 for maximum security.
SA Life Time Define the length of time before an IKE SA automatically renegotiates
in this field. It can range from 60 to 3 000 000 seconds (almost 35
days). A short SA life time increases security by forcing the two VPN
switches to update the encryption and authentication keys. However,
every time the VPN tunnel renegotiates, all users accessing remote
resources are temporarily disconnected.
Vista de pagina 241
1 2 ... 237 238 239 240 241 242 243 244 245 246 247 ... 450 451

Comentarios a estos manuales

Sin comentarios