Linksys QuickVPN Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN A - Page 121

Setting Up IPSec, VPN > IPSec Setup, Keying Mode, IKE with Preshared Key, Manual, Encryption

Page 121 highlights

Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the VPN Settings 5 Setting Up IPSec The IPSec Setup section of the VPN > IPSec VPN window displays the security parameters for configuring a VPN. To set up IPSec for the router, follow these steps: STEP 1 Click VPN > IPSec Setup. STEP 2 Configure the security parameters for VPN IPSec: • Keying Mode-The router supports both IKE with Preshared Key (automatic) and Manual key management. When choosing automatic key management, IKE (Internet Key Exchange) protocols are used to negotiate key material for SA. If manual key management is selected, no key negotiation is needed. Basically, manual key management is used in small static environments or for troubleshooting purpose. Notice that both sides must use the same Key Management method. • Encryption-The Encryption method determines the length of the key used to encrypt/decrypt ESP packets. 3DES is supported. Notice that both sides of the VPN tunnel must use the same Encryption method. • Authentication-Authentication determines a method to authenticate the ESP packets. Either MD5 or SHA1 may be selected. Both sides of the VPN tunnel must use the same Authentication method. - MD5-A one way hashing algorithm that produces a 128-bit digest. - SHA1-A one way hashing algorithm that produces a 160-bit digest. • Preshared Key- IKE uses the Pre-shared Key field to authenticate the remote IKE peer. Both character and hexadecimal value are acceptable in this field. for example; "My_@123" or "0x4d795f40313233." Both sides must use the same Pre-shared Key. • Key Lifetime-Specifies the lifetime of the IKE generated key. If the time expires, a new key is renegotiated automatically. The Key Lifetime may range from 1081 to 86400 seconds. The default value for Phase 1 is 28800 seconds, and default value for Phase 2 is 3600 seconds • Group- For Diffie-Hellman key negotiation. There are 3 groups available for ISAKMP SA establishment, 768-bit, 1024-bit, 1536-bit represent different bits used in Diffie-Hellman mode operation. The default value is Group 768bit. Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide 121

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233

Setting Up and Configuring the WRVS4400N Wireless-N Router
Configuring the VPN Settings
Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide
121
5
Setting Up IPSec
The IPSec Setup section of the VPN > IPSec VPN window displays the security
parameters for configuring a VPN.
To set up IPSec for the router, follow these steps:
STEP 1
Click
VPN > IPSec Setup
.
STEP 2
Configure the security parameters for VPN IPSec:
Keying Mode
—The router supports both
IKE with Preshared Key
(automatic) and
Manual
key management. When choosing automatic key
management, IKE (Internet Key Exchange) protocols are used to negotiate
key material for SA. If manual key management is selected, no key
negotiation is needed. Basically, manual key management is used in small
static environments or for troubleshooting purpose. Notice that both sides
must use the same Key Management method.
Encryption
—The Encryption method determines the length of the key used
to encrypt/decrypt ESP packets.
3DES
is supported. Notice that both sides
of the VPN tunnel must use the same Encryption method.
Authentication
—Authentication determines a method to authenticate the
ESP packets. Either
MD5
or
SHA1
may be selected. Both sides of the VPN
tunnel must use the same Authentication method.
-
MD5
—A one way hashing algorithm that produces a 128-bit digest.
-
SHA1
—A one way hashing algorithm that produces a 160-bit digest.
Preshared Key
— IKE uses the Pre-shared Key field to authenticate the
remote IKE peer. Both character and hexadecimal value are acceptable in
this field. for example; “My_@123” or “0x4d795f40313233.” Both sides must
use the same Pre-shared Key.
Key Lifetime
—Specifies the lifetime of the IKE generated key. If the time
expires, a new key is renegotiated automatically. The Key Lifetime may range
from 1081 to 86400 seconds. The default value for Phase 1 is 28800
seconds, and default value for Phase 2 is 3600 seconds
Group
— For Diffie-Hellman key negotiation. There are 3 groups available for
ISAKMP SA establishment, 768-bit, 1024-bit, 1536-bit represent different
bits used in Diffie-Hellman mode operation. The default value is Group 768-
bit.