Cisco RV042 Administration Guide - Page 146

Keep-Alive, AH Hash Algorithm, NetBIOS Broadcast, Dead Peer Detection DPD, NAT Traversal

Page 146 highlights

VPN Setting Up a Remote Access Tunnel for VPN Clients (Client To Gateway) 9 always accept compression, even if compression is not enabled. If you enable this feature for this router, also enable it on the client. - Keep-Alive: This feature enables the router to attempt to automatically re-establish the VPN connection if it is dropped. Check the box to enable this feature, or uncheck the box to disable it. - AH Hash Algorithm: The AH (Authentication Header) protocol describes the packet format and default standards for packet structure. With the use of AH as the security protocol, protection is extended forward into the IP header to verify the integrity of the entire packet. Check the box to use this feature. Then select an authentication method: MD5 or SHA1. MD5 produces a 128-bit digest to authenticate packet data. SHA1 produces a 160-bit digest to authenticate packet data. Both sides of the tunnel should use the same algorithm. - NetBIOS Broadcast: NetBIOS broadcast messages are used for name resolution in Windows networking, to identify resources such as computers, printers, and file servers. These messages are required by some software applications and Windows features such as Network Neighborhood. LAN broadcast traffic is typically not forwarded over a VPN tunnel. However, you can check this box to allow NetBIOS broadcasts from one end of the tunnel to be rebroadcast to the other end. - Dead Peer Detection (DPD) (available for Tunnel, not Group VPN): Check the box to enable the router to send periodic HELLO/ACK messages to check the status of the VPN tunnel. This feature can be used only when it is enabled on both ends of the VPN tunnel. Specify the interval between HELLO/ACK messages (how often you want the messages to be sent). - NAT Traversal: Network Address Translation (NAT) enables users with private LAN addresses to access Internet resources by using a publicly routable IP address as the source address. However, for inbound traffic, the NAT gateway has no automatic method of translating the public IP address to a particular destination on the private LAN. This issue prevents successful IPsec exchanges. If your VPN router is behind a NAT gateway, check this box to enable NAT traversal. Uncheck the box to disable this feature. The same setting must be used on both ends of the tunnel. Cisco Small Business RV0xx Series Routers Administration Guide 146

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199

VPN
Setting Up a Remote Access Tunnel for VPN Clients (Client To Gateway)
Cisco Small Business RV0xx Series Routers Administration Guide
146
9
always accept compression, even if compression is not enabled. If you
enable this feature for this router, also enable it on the client.
-
Keep-Alive:
This feature enables the router to attempt to automatically
re-establish the VPN connection if it is dropped. Check the box to enable
this feature, or uncheck the box to disable it.
-
AH Hash Algorithm:
The AH (Authentication Header) protocol describes
the packet format and default standards for packet structure. With the
use of AH as the security protocol, protection is extended forward into
the IP header to verify the integrity of the entire packet. Check the box to
use this feature. Then select an authentication method: MD5 or SHA1.
MD5 produces a 128-bit digest to authenticate packet data. SHA1
produces a 160-bit digest to authenticate packet data. Both sides of the
tunnel should use the same algorithm.
-
NetBIOS Broadcast:
NetBIOS broadcast messages are used for name
resolution in Windows networking, to identify resources such as
computers, printers, and file servers. These messages are required by
some software applications and Windows features such as Network
Neighborhood. LAN broadcast traffic is typically not forwarded over a
VPN tunnel. However, you can check this box to allow NetBIOS
broadcasts from one end of the tunnel to be rebroadcast to the other
end.
-
Dead Peer Detection (DPD)
(available for Tunnel, not Group VPN)
:
Check the box to enable the router to send periodic HELLO/ACK
messages to check the status of the VPN tunnel. This feature can be
used only when it is enabled on both ends of the VPN tunnel. Specify the
interval between HELLO/ACK messages (how often you want the
messages to be sent).
-
NAT Traversal:
Network Address Translation (NAT) enables users with
private LAN addresses to access Internet resources by using a publicly
routable IP address as the source address. However, for inbound traffic,
the NAT gateway has no automatic method of translating the public IP
address to a particular destination on the private LAN. This issue
prevents successful IPsec exchanges. If your VPN router is behind a NAT
gateway, check this box to enable NAT traversal. Uncheck the box to
disable this feature. The same setting must be used on both ends of the
tunnel.