TP-Link TL-ER6020 TL-ER6020 v1 User Guide - Page 90

Exchange Mode, Local ID Type, Local ID, Remote ID Type, Remote ID, IKE Proposal, Pre-shared Key, SA

Page 90 highlights

Exchange Mode: Select the IKE Exchange Mode in phase 1, and ensure the remote VPN peer uses the same mode.  Main: Main mode provides identity protection and exchanges more information, which applies to the scenarios with higher requirement for identity protection.  Aggressive: Aggressive Mode establishes a faster connection but with lower security, which applies to scenarios with lower requirement for identity protection. Local ID Type: Select the local ID type for IKE negotiation. IP Address: uses an IP address as the ID in IKE negotiation. FQDN: uses a name as the ID. Local ID: The local WAN IP will be inputted automatically if IP Address type is selected. If Name type is selected, enter a name for the local device as the ID in IKE negotiation Remote ID Type: Select the remote ID type for IKE negotiation. IP Address: uses an IP address as the ID in IKE negotiation. FQDN: uses a name as the ID. Remote ID: The remote gateway IP will be inputted automatically if IP Address type is selected. If Name type is selected, enter the name of the remote peer as the ID in IKE negotiation. IKE Proposal: Select the Proposal for IKE negotiation phase 1. Up to four proposals can be selected. Pre-shared Key: Enter the Pre-shared Key for IKE authentication, and ensure both the two peers use the same key. The key should consist of visible characters without blank space. SA Lifetime: Specify ISAKMP SA Lifetime in IKE negotiation. DPD: Enable or disable DPD (Dead Peer Detect) function. If enabled, the IKE endpoint can send a DPD request to the peer to inspect whether the IKE peer is alive. -85-

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168

-85-
Exchange Mode:
Select the IKE Exchange Mode in phase 1, and ensure the
remote VPN peer uses the same mode.
Main: Main mode provides identity protection and exchanges
more information, which applies to the scenarios with higher
requirement for identity protection.
Aggressive:
Aggressive
Mode
establishes
a
faster
connection but with lower security, which applies to scenarios
with lower requirement for identity protection.
Local ID Type:
Select the local ID type for IKE negotiation. IP Address: uses an
IP address as the ID in IKE negotiation. FQDN: uses a name as
the ID.
Local ID:
The local WAN IP will be inputted automatically if IP Address type
is selected. If Name type is selected, enter a name for the local
device as the ID in IKE negotiation
Remote ID Type:
Select the remote ID type for IKE negotiation. IP Address: uses an
IP address as the ID in IKE negotiation. FQDN: uses a name as
the ID.
Remote ID:
The remote gateway IP will be inputted automatically if IP Address
type is selected. If Name type is selected, enter the name of the
remote peer as the ID in IKE negotiation.
IKE Proposal:
Select the Proposal for IKE negotiation phase 1. Up to four
proposals can be selected.
Pre-shared Key:
Enter the Pre-shared Key for IKE authentication, and ensure both
the two peers use the same key. The key should consist of visible
characters without blank space.
SA Lifetime:
Specify ISAKMP SA Lifetime in IKE negotiation.
DPD:
Enable or disable DPD (Dead Peer Detect) function. If enabled,
the IKE endpoint can send a DPD request to the peer to inspect
whether the IKE peer is alive.