Netgear FVS318 FVS318v3 Reference Manual - Page 95

Table 6-1., VPN - Auto Policy Configuration Fields

Page 95 highlights

Reference Manual for the ProSafe VPN Firewall FVS318v3 The VPN - Auto Policy fields are defined in the following table. Table 6-1. VPN - Auto Policy Configuration Fields Field General Policy Name IKE Policy Remote VPN Endpoint Address Type Address Data SA Life Time IPSec PFS PFS Key Group Description These settings identify this policy and determine its major characteristics. The descriptive name of the VPN policy. Each policy should have a unique policy name. This name is not supplied to the remote VPN endpoint. It is only used to help you identify VPN policies. The existing IKE policies are presented in a drop-down list. Note: Create the IKE policy BEFORE creating a VPN - Auto policy. The address used to locate the remote VPN firewall or client to which you wish to connect. The remote VPN endpoint must have this FVS318v3's Local IP values entered as its Remote VPN Endpoint. • By its Fully Qualified Domain Name (FQDN) - your domain name. • By its IP Address. The address type used to locate the remote VPN firewall or client to which you wish to connect. • By its Fully Qualified Domain Name (FQDN) - your domain name. • By its IP Address. The address used to locate the remote VPN firewall or client to which you wish to connect. The remote VPN endpoint must have this FVS318v3's Local Identity Data entered as its Remote VPN Endpoint. • By its Fully Qualified Domain Name (FQDN) - your domain name. • By its IP Address. The duration of the Security Association before it expires. • Seconds - the amount of time before the SA expires. Over an hour is common (3600). • Kbytes - the amount of traffic before the SA expires. One of these can be set without setting the other. If enabled, security is enhanced by ensuring that the key is changed at regular intervals. Also, even if one key is broken, subsequent keys are no easier to break. Each key has no relationship to the previous key. If PFS is enabled, this setting determines the DH group bit size used in the key exchange. This must match the value used on the remote gateway. Advanced Virtual Private Networking 6-7 January 2005

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242

Reference Manual for the ProSafe VPN Firewall FVS318v3
Advanced Virtual Private Networking
6-7
January 2005
The VPN – Auto Policy fields are defined in the following table.
Table 6-1.
VPN – Auto Policy Configuration Fields
Field
Description
General
These settings identify this policy and determine its major characteristics.
Policy Name
The descriptive name of the VPN policy. Each policy should have a unique
policy name. This name is not supplied to the remote VPN endpoint. It is
only used to help you identify VPN policies.
IKE Policy
The existing IKE policies are presented in a drop-down list.
Note:
Create the IKE policy BEFORE creating a VPN - Auto policy.
Remote VPN Endpoint
The address used to locate the remote VPN firewall or client to which you
wish to connect. The remote VPN endpoint must have this FVS318v3’s
Local IP values entered as its Remote VPN Endpoint.
By its Fully Qualified Domain Name (FQDN) — your domain name.
By its IP Address.
Address Type
The address type used to locate the remote VPN firewall or client to which
you wish to connect.
By its Fully Qualified Domain Name (FQDN) — your domain name.
By its IP Address.
Address Data
The address used to locate the remote VPN firewall or client to which you
wish to connect. The remote VPN endpoint must have this FVS318v3’s
Local Identity Data entered as its Remote VPN Endpoint.
By its Fully Qualified Domain Name (FQDN) — your domain name.
By its IP Address.
SA Life Time
The duration of the Security Association before it expires.
Seconds — the amount of time before the SA expires. Over an hour is
common (3600).
Kbytes — the amount of traffic before the SA expires.
One of these can be set without setting the other.
IPSec PFS
If enabled, security is enhanced by ensuring that the key is changed at
regular intervals. Also, even if one key is broken, subsequent keys are no
easier to break. Each key has no relationship to the previous key.
PFS Key Group
If PFS is enabled, this setting determines the DH group bit size used in the
key exchange. This must match the value used on the remote gateway.