Netgear FVG318v1 FVG318 Reference Manual - Page 112

Manual Policy Parameters, Encryption Key-In, Integrity Key-In, Field, Description

Page 112 highlights

ProSafe 802.11g Wireless VPN Firewall FVG318 Reference Manual Table 6-1. VPN Manual and Auto Policy Configuration Fields (continued) Field Description Manual Policy Parameters The Manual Policy creates an SA (Security Association) based on static inputs SPI-Incoming; SPI-Outgoing Takes a hexadecimal value between 3 and 8 characters; for example: 0x1234 Encryption Algorithm: The algorithm used to encrypt the data: • Encryption Key-In: Encryption key of the inbound policy. The length of the key depends on the algorithm chosen. The length is in characters as follows: DES - 8 characters 3DES - 24 characters AES-128 - 16 characters AES-192 - 24 characters AES-256 - 32 characters • Encryption Key-Out: Encryption key of the outbound policy. The length of the key depends on the algorithm chosen. Lengths for the outbound policy encryption key are the same as for the inbound policy. Integrity Algorithm: Algorithm used to verify the integrity of the data. • Integrity Key-In: The integrity key (for Encapsulated Security Payload (ESP) with encryption mode) for the inbound policy and depends on the algorithm chosen: MD5 - 16 characters SHA-1 - 20 characters • Integrity Key-Out: The integrity key (for ESP with encryption mode) for the outbound policy and depends on the algorithm chosen. Lengths are the same as for the inbound mode. Auto Policy Parameters SA Life Time The duration of the Security Association before it expires. • Seconds - the amount of time before the SA expires. Over an hour is common (3600). • Kbytes - the amount of traffic before the SA expires. One of these can be set without setting the other. Encryption Algorithm The encryption algorithm used to encrypt the data: • DES - the default • 3DES - more secure Integrity Algorithm Algorithm used to verify the integrity of the data. The choices are: • MD5 - the default • SHA1 - more secure 6-6 Advanced Virtual Private Networking v1.0, September 2007

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176

ProSafe 802.11g Wireless VPN Firewall FVG318 Reference Manual
6-6
Advanced Virtual Private Networking
v1.0, September 2007
Manual Policy Parameters
The Manual Policy creates an SA (Security Association) based on static
inputs
SPI-Incoming; SPI-Outgoing
Takes a hexadecimal value between 3 and 8 characters; for example:
0x1234
Encryption Algorithm:
The algorithm used to encrypt the data:
Encryption Key-In
: Encryption key of the inbound policy. The length of
the key depends on the algorithm chosen. The length is in characters
as follows:
DES – 8 characters
3DES – 24 characters
AES-128 – 16 characters
AES-192 – 24 characters
AES-256 – 32 characters
Encryption Key-Out:
Encryption key of the outbound policy. The
length of the key depends on the algorithm chosen. Lengths for the
outbound policy encryption key are the same as for the inbound policy.
Integrity Algorithm:
Algorithm used to verify the integrity of the data.
Integrity Key-In
: The integrity key (for Encapsulated Security Payload
(ESP) with encryption mode) for the inbound policy and depends on
the algorithm chosen:
MD5 – 16 characters
SHA-1 – 20 characters
Integrity Key-Out:
The integrity key (for ESP with encryption mode)
for the outbound policy and depends on the algorithm chosen. Lengths
are the same as for the inbound mode.
Auto Policy Parameters
SA Life Time
The duration of the Security Association before it expires.
Seconds — the amount of time before the SA expires. Over an hour is
common (3600).
Kbytes — the amount of traffic before the SA expires.
One of these can be set without setting the other.
Encryption Algorithm
The encryption algorithm used to encrypt the data:
DES – the default
3DES – more secure
Integrity Algorithm
Algorithm used to verify the integrity of the data. The choices are:
MD5 – the default
SHA1 – more secure
Table 6-1.
VPN Manual and Auto Policy Configuration Fields (continued)
Field
Description