Netgear SRXN3205 SRXN3205 Reference Manual - Page 116

Extended Authentication, Enable Dead Peer Detection, if yes

Page 116 highlights

ProSafe Wireless-N VPN Firewall SRXN3205 Reference Manual - Authentication Method. Select Pre-shared Key for a simple password based key. Selecting RSA-Signature will disable the Pre-shared key text box and uses the Active Self Certificate uploaded in the Certificates page. In that case, a certificate must be configured in order for RSA-Signature to work. - Pre-shared Key Note: The " (Double Quote) character is not supported for a Pre-shared Key. - Diffie-Hellman (DH) Group. This method is used when exchanging keys. The DH group sets the number of bits. The VPN Wizard default setting is Group 2. (This setting must match the remote VPN.) - SA-Lifetime (sec) - Enable Dead Peer Detection, if yes Dead Peer Detection is used to detect whether the Peer is alive or not. If the peer is detected as Dead, it deletes the IPSec and IKE Security Association. - Detection Period (Seconds): Detection Period is the interval between consecutive DPD R-U-THERE messages. DPD R-U-THERE messages are sent only when the IPSec traffic is idle. - Reconnect after failure count: Maximum number of DPD failures allowed before tearing down the connection. • Extended Authentication. The XAUTH Configuration Edge Device: Select this option to use this router as a VPN concentrator where one or more gateway tunnels terminate. The authentication modes are: - User Database: User accounts created in the router are used to authenticate users (under the VPN Client menu on the User Database page). - RADIUS: The router will connect to a RADIUS server and pass on the credentials it receives from the VPN Client. The connection between the router and the RADIUS server can be secured with the authentication protocol supported by the server (PAP or CHAP). RADIUS server settings are configured under the VPN Client menu on the RADIUS Client page. Note: If RADIUS - PAP is selected, the router will first check in the User Database to see if the user credentials are available. If the user account is not present, the router will then connect to the RADIUS server. 6-14 Virtual Private Networking Using IPsec v1.0, October 2008

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218

ProSafe Wireless-N VPN Firewall SRXN3205 Reference Manual
6-14
Virtual Private Networking Using IPsec
v1.0, October 2008
Authentication Method. Select Pre-shared Key for a simple password based key. Selecting
RSA-Signature will disable the Pre-shared key text box and uses the Active Self
Certificate uploaded in the Certificates page. In that case, a certificate must be configured
in order for RSA-Signature to work.
Pre-shared Key
Diffie-Hellman (DH) Group. This method is used when exchanging keys. The DH group
sets the number of bits. The VPN Wizard default setting is Group 2. (This setting must
match the remote VPN.)
SA-Lifetime (sec)
Enable Dead Peer Detection, if yes
Dead Peer Detection is used to detect whether the Peer is alive or not. If the peer is
detected as Dead, it deletes the IPSec and IKE Security Association.
Detection Period (Seconds): Detection Period is the interval between consecutive
DPD R-U-THERE messages. DPD R-U-THERE messages are sent only when the
IPSec traffic is idle.
Reconnect after failure count: Maximum number of DPD failures allowed before
tearing down the connection.
Extended Authentication
. The XAUTH Configuration
Edge Device: Select this option to use this router as a VPN concentrator where one or more
gateway tunnels terminate. The authentication modes are:
User Database: User accounts created in the router are used to authenticate users (under
the VPN Client menu on the User Database page).
RADIUS: The router will connect to a RADIUS server and pass on the credentials it
receives from the VPN Client. The connection between the router and the RADIUS server
can be secured with the authentication protocol supported by the server (PAP or CHAP).
RADIUS server settings are configured under the VPN Client menu on the RADIUS
Client page.
Note:
The “ (Double Quote) character is not supported for a Pre-shared Key.
Note:
If RADIUS – PAP is selected, the router will first check in the User
Database to see if the user credentials are available. If the user account is
not present, the router will then connect to the RADIUS server.