Netgear FVS338 FVS338 Reference Manual - Page 100

VPN Policy Operation, VPN Policy Table, Status, Enable, Disable, Keep alive, Enable Keep Alive

Page 100 highlights

FVS338 ProSafe VPN Firewall 50 Reference Manual In addition, a CA (Certificate Authority) can also be used to perform authentication (see "Certificates" on page 5-33). To use a CA, each VPN Gateway must have a Certificate from the CA. For each Certificate, there is both a "Public Key" and a "Private Key". The "Public Key" is freely distributed, and is used to encrypt data. The receiver then uses their "Private Key" to decrypt the data (without the Private Key, decryption is impossible). CAs can be beneficial since using them reduces the amount of data entry required on each VPN Endpoint. VPN Policy Operation The VPN Policies screen allows you to add additional policies-either Auto or Manual-and to manage the VPN policies already created. You can edit policies, enable or disable them, or delete them entirely. The rules for VPN policy use conform to: 1. Traffic covered by a policy will automatically be sent via a VPN tunnel. 2. The VPN tunnel is created according to the parameters in the SA (Security Association). 3. The remote VPN Endpoint must have a matching SA, or it will refuse the connection. VPN Policy Table When you use the VPN Wizard to set up a VPN tunnel, both a VPN Policy and an IKE Policy is established and populated in both Tables on the VPN Policies screen. The name you selected as the VPN Tunnel connection name during Wizard setup identifies both the VPN Policy and IKE Policy. You can also edit exiting policies, add new VPN policies directly or change the policy hierarchy to the Policy Table. The Policy Table contains the following fields: • ! (Status). Indicates whether the policy is enabled (green circle) or disabled (grey circle). To Enable or Disable a Policy, check the radio box adjacent to the circle and click Enable or Disable, as required. • Name. Each policy is given a unique name (the Connection Name when using the VPN Wizard). Client Policies are annotated by an "*". • Type. The Type is "Auto" or "Manual" as described previously (Auto is used during VPN Wizard configuration). • Keep alive: It periodically sends ping packets to the host on the peer side of the network to keep the tunnel alive. - Enable Keep Alive: Check to enable. - Ping IP Address: Enter the IP Address to which ping packets need to be sent. - Detection period: Router sends ping packets periodically at regular intervals of time which is specified by the user. 5-6 Virtual Private Networking v1.0, March 2008

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198

FVS338 ProSafe VPN Firewall 50 Reference Manual
5-6
Virtual Private Networking
v1.0, March 2008
In addition, a CA (Certificate Authority) can also be used to perform authentication (see
“Certificates” on page 5-33
). To use a CA, each VPN Gateway must have a Certificate from the
CA. For each Certificate, there is both a “Public Key” and a “Private Key”. The “Public Key” is
freely distributed, and is used to encrypt data. The receiver then uses their “Private Key” to decrypt
the data (without the Private Key, decryption is impossible). CAs can be beneficial since using
them reduces the amount of data entry required on each VPN Endpoint.
VPN Policy Operation
The VPN Policies screen allows you to add additional policies—either Auto or Manual—and to
manage the VPN policies already created. You can edit policies, enable or disable them, or delete
them entirely. The rules for VPN policy use conform to:
1.
Traffic covered by a policy will automatically be sent via a VPN tunnel.
2.
The VPN tunnel is created according to the parameters in the SA (Security Association).
3.
The remote VPN Endpoint must have a matching SA, or it will refuse the connection.
VPN Policy Table
When you use the VPN Wizard to set up a VPN tunnel, both a VPN Policy and an IKE Policy is
established and populated in both Tables on the VPN Policies screen. The name you selected as the
VPN Tunnel connection name during Wizard setup identifies both the VPN Policy and IKE Policy.
You can also edit exiting policies, add new VPN policies directly or change the policy hierarchy to
the Policy Table. The Policy Table contains the following fields:
! (Status)
. Indicates whether the policy is enabled (green circle) or disabled (grey circle). To
Enable or Disable a Policy, check the radio box adjacent to the circle and click
Enable
or
Disable
, as required.
Name
. Each policy is given a unique name (the Connection Name when using the VPN
Wizard). Client Policies are annotated by an “*”.
Type
. The Type is “Auto” or “Manual” as described previously (Auto is used during VPN
Wizard configuration).
Keep alive
: It periodically sends ping packets to the host on the peer side of the network to
keep the tunnel alive.
Enable Keep Alive
: Check to enable.
Ping IP Address
: Enter the IP Address to which ping packets need to be sent.
Detection period
: Router sends ping packets periodically at regular intervals of time
which is specified by the user.