TP-Link TD-W8960N User Guide - Page 66

Show Advanced Settings, Key Exchange Method

Page 66 highlights

TD-W8960N Wireless N ADSL2+ Modem Router User Guide ¾ IP Subnetmask: Enter the subnetmask of the remote LAN. ( For example: Input 255.255.255.0 in both Device1 and Device2) ¾ Key Exchange Method: Select Auto (IKE) or Manual. ¾ Authentication Method: Select Pre-Shared Key (recommended) or Certificate (X.509). ¾ Pre-Shared Key: Input the Pre-Shared key for Authentication. (For example: Input 12345678) ¾ Perfect Forward Secrecy: PFS is an additional security protocol. We recommend you leave the Advanced Settings as default value. After complete the basic settings and click Save/Apply in both Device1 and Device2, PCs in LAN1 could conmmunicate with PCs in remote LAN2. (For example: You can ping the IP address of PC2 which is 192.168.2.100 in PC1) ) Note: The VPN Servers Endpoint from both ends must use the same pre-shared keys and Perfect Forward Secrecy settings. Click Show Advanced Settings and then you can configure the Advanced Settings. ¾ Main Mode: Select Main Mode to configure the standard negotiation parameters for IKE phase1. ¾ Aggressive Mode: Select Aggressive Mode to configure IKE phase1 of the VPN Tunnel to carry out negotiation in a shorter amount of time. (Not Recommended-Less Secure) ) Note: The difference between the two is that aggressive mode will pass more information in fewer packets, with the benefit of slightly faster connection establishment, at the cost of transmitting the identities of the security firewall in the clear. When using aggressive mode, some configuration 59

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110

TD-W8960N
Wireless N ADSL2+ Modem Router User Guide
¾
IP Subnetmask:
Enter the subnetmask of the remote LAN. ( For example: Input
255.255.255.0
in both
Device1
and
Device2
)
¾
Key Exchange Method:
Select Auto (IKE) or Manual.
¾
Authentication Method:
Select Pre-Shared Key (recommended) or Certificate (X.509).
¾
Pre-Shared Key:
Input the Pre-Shared key for Authentication. (For example: Input 12345678)
¾
Perfect Forward Secrecy:
PFS is an additional security protocol.
We recommend you leave the Advanced Settings as default value.
After complete the basic settings and click Save/Apply in both
Device1
and
Device2
, PCs in LAN1
could conmmunicate with PCs in remote LAN2. (For example: You can ping the IP address of PC2
which is 192.168.2.100 in PC1)
)
Note:
The VPN Servers Endpoint from both ends must use the same pre-shared keys and Perfect
Forward Secrecy settings.
Click
Show Advanced Settings
and then you can configure the Advanced Settings.
¾
Main Mode:
Select Main Mode to configure the standard negotiation parameters for IKE
phase1.
¾
Aggressive Mode:
Select Aggressive Mode to configure IKE phase1 of the VPN Tunnel to
carry out negotiation in a shorter amount of time. (Not Recommended-Less Secure)
)
Note:
The difference between the two is that aggressive mode will pass more information in fewer
packets, with the benefit of slightly faster connection establishment, at the cost of transmitting the
identities of the security firewall in the clear. When using aggressive mode, some configuration
59