D-Link DWC-1000 DWC-1000 User's Guide - Page 102

Checked = enable PFS., PFS Key Group

Page 102 highlights

VPN Settings Field Description This section is used when Policy Type = Auto Policy under the General section of this page. These settings configure Phase 2 negotiations and should match the Phase 2 settings on the remote tunnel endpoint. SA Lifetime Enter the duration of the Security Association and select the unit (seconds or Kbytes) from the drop-down list. • Seconds = measures the SA Lifetime in seconds. After the specified number of seconds passes, the Security Association is renegotiated. Default value is 3600 seconds. Minimum value is 300 seconds. • Kbytes = measures the SA Lifetime in kilobytes. After the specified number of kilobytes of data is transferred, the SA is renegotiated. Minimum value is 1920000 KB. When configuring a Lifetime in kilobytes (also known as lifebytes), two SAs are created for each policy. One SA for inbound traffic and one for outbound traffic. Due to differences in the upstream and downstream traffic flows, the SA may expire asymmetrically. For example, if the downstream traffic is very high, the lifebyte for a download stream may expire frequently. The lifebyte of the upload stream may not expire as frequently. Therefore, set the values reasonably to reduce the difference in expiry frequencies of the SAs; otherwise, this asymmetry might exhaust system resources. Lifebyte specifications are recommended for advanced users only. Encryption Algorithm Check the algorithm used to encrypt the data. Integrity Algorithm Check the algorithm used to verify the integrity of the data. PFS Key Group Enables or disables Perfect Forward Secrecy (PFS) to improve security. While slower, this protocol helps to prevent eavesdroppers by ensuring that a Diffie-Hellman exchange is performed for every phase-2 negotiation. Choices are: • Checked = enable PFS. • Unchecked = disable PFS. 102 DWC-1000 Wireless Controller User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242

VPN Settings
102
DWC-1000 Wireless Controller User’s Guide
Field
Description
This section is used when Policy Type = Auto Policy under the General section of this page. These settings configure Phase 2
negotiations and should match the Phase 2 settings on the remote tunnel endpoint.
SA Lifetime
Enter the duration of the Security Association and select the unit (seconds or Kbytes) from the
drop-down list.
Seconds = measures the SA Lifetime in seconds. After the specified number of seconds
passes, the Security Association is renegotiated. Default value is 3600 seconds. Minimum
value is 300 seconds.
Kbytes = measures the SA Lifetime in kilobytes. After the specified number of kilobytes of data
is transferred, the SA is renegotiated. Minimum value is 1920000 KB.
When configuring a Lifetime in kilobytes (also known as lifebytes), two SAs are created for each
policy. One SA for inbound traffic and one for outbound traffic. Due to differences in the upstream
and downstream traffic flows, the SA may expire asymmetrically. For example, if the downstream
traffic is very high, the lifebyte for a download stream may expire frequently. The lifebyte of the
upload stream may not expire as frequently. Therefore, set the values reasonably to reduce the
difference in expiry frequencies of the SAs; otherwise, this asymmetry might exhaust system
resources. Lifebyte specifications are recommended for advanced users only.
Encryption Algorithm
Check the algorithm used to encrypt the data.
Integrity Algorithm
Check the algorithm used to verify the integrity of the data.
PFS Key Group
Enables or disables Perfect Forward Secrecy (PFS) to improve security. While slower, this
protocol helps to prevent eavesdroppers by ensuring that a Diffie-Hellman exchange is
performed for every phase-2 negotiation. Choices are:
Checked = enable PFS.
Unchecked = disable PFS.