ZyXEL Vantage CNM User Guide - Page 480
Remote Access, Table 211
View all ZyXEL Vantage CNM manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 480 highlights
Chapter 20 VPN Community Table 211 VPN Management > VPN Community > Add/Edit (continued) FIELD DESCRIPTION Hub Gateway This is avaialble if you select the Hub & Spoke community type. You have to select only one device in this section. Spoke Gateways This is avaialble if you select the Hub & Spoke community type. You have to select at least one device in this section. Central Gateway This is avaialble if you select the Remote Access community type. You have to select only one device in this section. Satellite Gateways This is avaialble if you select the Remote Access community type. You have to select at least one device in this section. # This is the number of an individual entry. Device Name This field displays the device name. My IP/Domain This field identifies the WAN IP address or domain name of the member gateway. Local Network Add Edit Total Records Phase 1 Pre-Shared Key Negotiation Mode Encryption Algorithm Authentication Algorithm Note: When you select Remote Access for the community type, make sure the central gateway's MyIP is a fixed IP address. This is the network behind the member gateway. A network policy specifies which devices (behind the IPSec routers) can use the VPN tunnel. Click this to open the screen where you can select VPN gateways in this community. Click this to edit the selected VPN gateway in this community. This entry displays the total number of records on the current page of the list. Select Auto-generate the Vantage CNM generates a pre-shared key. Or select User-defined and type a key from 8 to 31 casesensitive ASCII characters or from 16 to 62 hexadecimal ("0-9", "AF") characters. You must precede a hexadecimal key with a "0x (zero x), which is not counted as part of the 16 to 62 character range for the key. For example, in "0x0123456789ABCDEF", 0x denotes that the key is hexadecimal and 0123456789ABCDEF is the key itself. Select Main or Aggressive from the drop-down list box. Select which key size and encryption algorithm to use in the IKE SA. Choices are: DES - a 56-bit key with the DES encryption algorithm 3DES - a 168-bit key with the DES encryption algorithm AES - a 128-bit key with the AES encryption algorithm The Vantage CNM and the remote IPSec router must use the same algorithms and keys. Longer keys require more processing power, resulting in increased latency and decreased throughput. Select which hash algorithm to use to authenticate packet data in the IKE SA. Choices are SHA1 and MD5. SHA1 is generally considered stronger than MD5, but it is also slower. 480 Vantage CNM User's Guide