Netgear N750-WiFi User Manual - Page 131

Enable PFS Perfect Forward Secrecy, Fully Qualified User Name

Page 131 highlights

N750 Wireless Dual Band Gigabit ADSL Modem Router DGND4000 - Direction/Type. This setting is used when determining if the IKE policy matches the current traffic. Select the desired option. - Responder only. Incoming connections are allowed, but outgoing connections are blocked. - Initiator and Responder. Both incoming and outgoing connections are allowed. - Exchange Mode. Currently, only Main Mode is supported. Ensure that the remote VPN endpoint is set to use Main Mode. - Diffie-Hellman (DH) Group. The Diffie-Hellman algorithm is used when the connection exchanges keys. The DH Group setting determines the bit size used in the exchange. This value must match the value used on the remote VPN gateway. - Local Identity Type. Select the desired option to match the Remote Identity Type setting on the remote VPN endpoint. - WAN IP Address. Your Internet IP address. - Fully Qualified Domain Name. Your domain name. - Fully Qualified User Name. Your name, email address, or other ID. - Local Identity Data. Enter the data for the selection. If WAN IP Address is selected, no input is required. - Remote Identity Type. Select the desired option to match the Local Identity Type setting on the remote VPN endpoint. - IP Address. The Internet IP address of the remote VPN endpoint. - Fully Qualified Domain Name. The domain name of the remote VPN endpoint. - Fully Qualified User Name. The name, email address, or other ID of the remote VPN endpoint. - Remote Identity Data. Enter the data for the selection. If IP Address is selected, no input is required. • Parameters. - Encryption Algorithm. The encryption algorithm used for both IKE and IPSec. This setting must match the setting used on the remote VPN gateway. - Authentication Algorithm. The authentication algorithm used for both IKE and IPSec. This setting must match the setting used on the remote VPN gateway. - Pre-shared Key. The key has to be entered both here and on the remote VPN gateway. - SA Life Time. This setting determines the time interval before the SA (security association) expires. (It is automatically reestablished as required.) While using a short time period (or data amount) increases security, it also degrades performance. It is common to use periods over an hour (3600 seconds) for the SA lifetime. This setting applies to both IKE and IPSec SAs. - Enable PFS (Perfect Forward Secrecy). If enabled, security is enhanced by ensuring that the key is changed at regular intervals. Also, even if one key is broken, subsequent keys are no easier to break. (Each key has no relationship to the previous key.) Advanced Settings 131

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153

Advanced Settings
131
N750 Wireless Dual Band Gigabit ADSL Modem Router DGND4000
-
Direction/Type
. This setting is used when determining if the IKE policy matches
the current traffic. Select the desired option.
-
Responder only
. Incoming connections are allowed, but outgoing connections
are blocked.
-
Initiator and Responder
. Both incoming and outgoing connections are allowed.
-
Exchange Mode
. Currently, only Main Mode is supported. Ensure that the remote
VPN endpoint is set to use Main Mode.
-
Diffie-Hellman (DH) Group
. The Diffie-Hellman algorithm is used when the
connection exchanges keys. The DH Group setting determines the bit size used
in the exchange. This value must match the value used on the remote VPN
gateway.
-
Local Identity Type
. Select the desired option to match the Remote Identity Type
setting on the remote VPN endpoint.
-
WAN IP Address
. Your Internet IP address.
-
Fully Qualified Domain Name
. Your domain name.
-
Fully Qualified User Name
. Your name, email address, or other ID.
-
Local Identity Data
. Enter the data for the selection. If WAN IP Address is
selected, no input is required.
-
Remote Identity Type
. Select the desired option to match the Local Identity Type
setting on the remote VPN endpoint.
-
IP Address
. The Internet IP address of the remote VPN endpoint.
-
Fully Qualified Domain Name
. The domain name of the remote VPN endpoint.
-
Fully Qualified User Name
. The name, email address, or other ID of the remote
VPN endpoint.
-
Remote Identity Data
. Enter the data for the selection. If IP Address is selected,
no input is required.
Parameters
.
-
Encryption Algorithm
. The encryption algorithm used for both IKE and IPSec.
This setting must match the setting used on the remote VPN gateway.
-
Authentication Algorithm
. The authentication algorithm used for both IKE and
IPSec. This setting must match the setting used on the remote VPN gateway.
-
Pre-shared Key
. The key has to be entered both here and on the remote VPN
gateway.
-
SA Life Time
. This setting determines the time interval before the SA (security
association) expires. (It is automatically reestablished as required.) While using a
short time period (or data amount) increases security, it also degrades
performance. It is common to use periods over an hour (3600 seconds) for the SA
lifetime. This setting applies to both IKE and IPSec SAs.
-
Enable PFS (Perfect Forward Secrecy)
. If enabled, security is enhanced by
ensuring that the key is changed at regular intervals. Also, even if one key is
broken, subsequent keys are no easier to break. (Each key has no relationship to
the previous key.)