Digi ConnectPort X4 User's Guide Page 85

  • Download
  • Add to my manuals
  • Print
  • Page
    / 271
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 84
Configuration through the web interface
85
ISAKMP Phase 2 Settings:
The SAs used for bulk data transfer are created during phase 2. The phase 2 settings
you specify will determine the level of security used when devices on the local
private network communicate with devices on the remote private network. As with
the other settings, the both the Digi unit and the remote VPN device must be
configured to use the same values. If more than one policy is specified, the VPN
devices will use the most secure policy that they both have been configured to
support.
General Security Settings for Phase 2
Diffie-Hellman: Select the Diffie-Hellman group used to generate keys. Larger
groups are more secure.
ISAKMP Phase 2 Policies
Encryption: The encryption algorithm used for encrypting data and the length of
the key. The longer the key the more secure it is. There are three supported
encryption algorithms including DES, 3-DES, and AES. DES encryption uses 64-
bit keys, 3-DES encryption uses 192-bit keys, and AES encryption uses 256-bit
keys.
Authentication: The authentication algorithm used in authenticating clients. There
are two supported authentication algorithms including MD5 and SHA1. MD5
authentication uses 128-bit keys and SHA1 uses 160-bit keys. The SHA1 algorithm
is more secure than MD5.
SA Lifetime: The maximum length of the Phase 2 security association (SA), in
seconds. After the SA has been negotiated, the SA lifetime begins. Once the
lifetime has completed, a new set of SA policies are negotiated with the remote
VPN endpoint.
Page view 84
1 2 ... 80 81 82 83 84 85 86 87 88 89 90 ... 270 271

Comments to this Manuals

No comments