ZyXEL LTE5121 User Guide - Page 155

VPN Monitor Screen, Technical Reference

Page 155 highlights

Chapter 16 VPN Table 62 IPSec VPN: Add LABEL Perfect Forward Secrecy (PFS) DESCRIPTION Select whether or not you want to enable Perfect Forward Secrecy (PFS) PFS changes the root key that is used to generate encryption keys for each IPSec SA. The longer the key, the more secure the encryption, but also the longer it takes to encrypt and decrypt information. Both routers must use the same DH key group. Choices are: Diffie-Hellman Group2 - use a 1024-bit random number Diffie-Hellman Group5 - use a 1536-bit random number DPD Active Diffie-Hellman Group14 - use a 2048-bit random number Enable Dead Peer Detection (DPD) Active check box if you want the LTE Device to make sure the remote IPSec router is there before it transmits data through the IKE SA. The remote IPSec router must support DPD. If the remote IPSec router does not respond, the LTE Device shuts down the IKE SA. 16.4 VPN Monitor Screen Use this screen to view active VPN connections. The following figure helps explain the main fields in the web configurator. Click Security > VPN > Monitor to open this screen as shown next. Figure 105 Monitor This screen contains the following fields: Table 63 Monitor LABEL DESCRIPTION # This is the VPN policy index number. Status This displays if the VPN policy is connected. Tunnel Name Enter the name of the VPN connection. IPSec Algorithm This displays the encryption algorithm being used for the VPN connection. Refresh Click this button to refresh the information on the screen. 16.5 Technical Reference This section provides some technical background information about the topics covered in this section. LTE-5121 User's Guide 155

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234

Chapter 16 VPN
LTE-5121 User’s Guide
155
16.4
VPN Monitor Screen
Use this screen to view active VPN connections. The following figure helps explain the main fields in
the web configurator.
Click
Security > VPN > Monitor
to open this screen as shown next.
Figure 105
Monitor
This screen contains the following fields:
16.5
Technical Reference
This section provides some technical background information about the topics covered in this
section.
Perfect
Forward
Secrecy (PFS)
Select whether or not you want to enable Perfect Forward Secrecy (PFS)
PFS changes the root key that is used to generate encryption keys for each IPSec
SA. The longer the key, the more secure the encryption, but also the longer it
takes to encrypt and decrypt information. Both routers must use the same DH
key group. Choices are:
Diffie-Hellman Group2
- use a 1024-bit random number
Diffie-Hellman Group5
- use a 1536-bit random number
Diffie-Hellman Group14
- use a 2048-bit random number
DPD Active
Enable Dead Peer Detection (DPD) Active check box if you want the LTE Device
to make sure the remote IPSec router is there before it transmits data through
the IKE SA. The remote IPSec router must support DPD.
If the remote IPSec
router does not respond, the LTE Device shuts down the IKE SA.
Table 62
IPSec VPN: Add
LABEL
DESCRIPTION
Table 63
Monitor
LABEL
DESCRIPTION
#
This is the VPN policy index number.
Status
This displays if the VPN policy is connected.
Tunnel Name
Enter the name of the VPN connection.
IPSec Algorithm
This displays the encryption algorithm being used for the VPN connection.
Refresh
Click this button to refresh the information on the screen.