Lantronix SGX 5150 User Guide - Page 60

Remote Network, Local Network, Key Management, ISAKMP Phase 1 IKE, Unreachable Host Detection

Page 60 highlights

6: Network Settings VPN Setting Description Remote Network Endpoint Enter the remote VPN Gateway's IP Address. Subnet Enter the subnet behind the VPN Gateway. ID Enter the identifier expected to receive from the remote host during Phase 1 negotiation. Router/Next Hop Enter the next-hop gateway IP address for the VPN Gateway. Local Network Subnet Enter the subnet the local devices have access to or can be accessed from the VPN connection. ID Enter the identifier sent to the remote host during Phase 1 negotiation. Router/Next Hop Enter the next-hop gateway IP address for this connection to the public network. Key Management Perfect Forward Secrecy (PFS) Select to enable or disable the Perfect Forward Secrecy. Enabling this feature will require IKE to generate a new set of keys in Phase 2 rather than using the same key generated in Phase 1. Pre-shared Key (PSK) Enter the Pre-Shared Key used in the IPSec setting between the Local and VPN Gateway. ISAKMP Phase 1 (IKE) Aggressive Mode Select to enable or disable Aggressive Mode. In Aggressive mode, IKE tries to combine as much information into fewer packets while maintaining security. Aggressive mode is slightly faster but less secure. NAT Traversal Select to enable or disable NAT Traversal. If there is an external NAT device between VPN tunnels, the user must enable NAT Traversal. Encryption Select the encryption algorithm in key exchange from the drop-down menu. Authentication Select the hash algorithm in key exchange from the drop-down menu. DH Group Select the Diffie-Hellman (DH) groups (the Key Exchange group between the Remote and VPN Gateways) from the drop-down menu. IKE Lifetime Enter the number of hours for the IKE SA lifetime. ISAKMP Phase 2 (ESP) Encryption Select the encryption algorithm in data exchange from the drop-down menu. Authentication Select the hash algorithm in data exchange from the drop-down menu. DH Group Select the Diffie-Hellman (DH) groups (the Key Exchange group between the Remote and VPN Gateways) for Phase 2 from the drop-down menu. SA Lifetime Enter the number of hours for the SA lifetime in Phase 2. Unreachable Host Detection Host Enter the unreachable detection host monitoring the connectivity with the host on the remote network. Ping Interval Enter the Ping Interval to monitor connectivity with a host on the remote network. Max Tries Enter the number of Max Tries for pinging the host before the VPN tunnel is restarted. SGX 5150 IoT Device Gateway User Guide 60

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129

6: Network Settings
SGX 5150 IoT Device Gateway User Guide
60
Remote Network
Endpoint
Enter the remote VPN Gateway’s IP Address.
Subnet
Enter the subnet behind the VPN Gateway.
ID
Enter the identifier expected to receive from the remote host during Phase 1
negotiation.
Router/Next Hop
Enter the next-hop gateway IP address for the VPN Gateway.
Local Network
Subnet
Enter the subnet the local devices have access to or can be accessed from
the VPN connection.
ID
Enter the identifier sent to the remote host during Phase 1 negotiation.
Router/Next Hop
Enter the next-hop gateway IP address for this connection to the public
network.
Key Management
Perfect Forward Secrecy
(PFS)
Select to enable or disable the Perfect Forward Secrecy. Enabling this
feature will require IKE to generate a new set of keys in Phase 2 rather than
using the same key generated in Phase 1.
Pre-shared Key (PSK)
Enter the Pre-Shared Key used in the IPSec setting between the Local and
VPN Gateway.
ISAKMP Phase 1 (IKE)
Aggressive Mode
Select to enable or disable Aggressive Mode. In Aggressive mode, IKE tries
to combine as much information into fewer packets while maintaining
security. Aggressive mode is slightly faster but less secure.
NAT Traversal
Select to enable or disable NAT Traversal. If there is an external NAT device
between VPN tunnels, the user must enable NAT Traversal.
Encryption
Select the encryption algorithm in key exchange from the drop-down menu.
Authentication
Select the hash algorithm in key exchange from the drop-down menu.
DH Group
Select the Diffie-Hellman (DH) groups (the Key Exchange group between the
Remote and VPN Gateways) from the drop-down menu.
IKE Lifetime
Enter the number of hours for the IKE SA lifetime.
ISAKMP Phase 2 (ESP)
Encryption
Select the encryption algorithm in data exchange from the drop-down menu.
Authentication
Select the hash algorithm in data exchange from the drop-down menu.
DH Group
Select the Diffie-Hellman (DH) groups (the Key Exchange group between the
Remote and VPN Gateways) for Phase 2 from the drop-down menu.
SA Lifetime
Enter the number of hours for the SA lifetime in Phase 2.
Unreachable Host Detection
Host
Enter the unreachable detection host monitoring the connectivity with the
host on the remote network.
Ping Interval
Enter the Ping Interval to monitor connectivity with a host on the remote
network.
Max Tries
Enter the number of Max Tries for pinging the host before the VPN tunnel is
restarted.
VPN Setting
Description