Page 81 / 143 Scroll up to view Page 76 - 80
Billion 800VGT Router
IKE
(Internet
key
Exchange)
Mode:
Select
IKE
mode
to
Main
mode
or
Aggressive
mode.
This
IKE
provides
secured
key
generation
and
key
management.
IKE Proposal:
Hash
Function:
This
is
a
Message
Digest
algorithm
which
coverts
any
length
of
a
message
into
a
unique set
of
bits.
You
can
use
either
MD5
(Message
Digest)
or
SHA-1
(Secure
Hash
Algorithm)
algorithms.
SHA1
is
more
resistant
to
brute-force
attacks
than
MD5,
however
it
is
slower.
²
MD5:
A
one-way
hashing
algorithm
that
produces
a
128±bit
hash.
²
SHA1:
A
one-way
hashing
algorithm
that
produces
a
160±bit
hash
Encryption:
Select
the
encryption
method
from
the
pull-down
menu.
There
are
several
options,
DES
,
3DES
and
AES
(128,
192
and
256)
.
3DES
and
AES
are
more
powerful
but
increase
latency.
²
DES:
Stands
for
Data
Encryption
Standard,
it
uses
56
bits
as
an
encryption
method.
²
3DES:
Stands
for
Triple
Data
Encryption
Standard,
it
uses
168
(56*3)
bits
as
an
encryption
method.
²
AES:
Stands
for
Advanced
Encryption
Standards,
you
can
use
128,
192
or
256
bits
as
encryption
method.
Diffie-Hellman
Group:
It
is
a
public-key
cryptography
protocol
that
allows
two
parties
to
establish
a
shared
secret
over
an
unsecured
communication
channel
(i.e.
over
the
Internet).
There
are
three
modes,
MODP
768-bit,
MODP
1024-bit
and
MODP
1536-bit.
MODP
stands
for
Modular
Exponentiation
Groups.
Local
ID:
²
Type:
Specify
local
ID
type.
²
Content:
Input
ID’s
information,
like
domain
name
www.ipsectest.com
.
Remote
ID:
²
Type:
Specify
Remote
ID
type.
²
Identifier:
Input
remote
ID’s
information,
like
domain
name
www.ipsectest.com
.
SA
Lifetime:
Specify
the
number
of
minutes
that
a
Security
Association
(SA)
will
stay
active
before
new
encryption
and
authentication
key
will
be
exchanged.
There
are
two
kinds
of
SAs,
IKE
and
IPSec.
IKE
negotiates
and
establishes
SA
on
behalf
of
IPSec,
an
IKE
SA
is
used
by
IKE.
²
Phase
1
(IKE):
U
sed
to
issue
an
initial
connection
request
for
a
new
VPN
tunnel.
Any
value
can
be
selected
between
5
and
15,000
minutes.
The
default
is
480
minutes.
²
Phase
2
(IPSec):
Used
to
negotiate
and
establish
secure
authentication.
Any
value
can
be
selected
between
5
and
15,000
minutes.
The
default
is
60
minutes.
A
short
SA
time
increases
security
by
forcing
the
two
parties
to
update
the
keys.
However,
every
time
the
VPN
tunnel
re-negotiates,
access
through
the
tunnel
will
be
temporarily
disconnected.
Ping to Keep
Alive:
PING
to
the
IP:
The
router
is
able
to
IP
Ping
the
remote
PC
with
a
specified
IP
address
and
alert
the
user
when
the
connection
fails.
Once
the
alert
message
is
received,
the
router
will
drop
this
tunnel
connection.
The
connection
will
need
to
be
re-established.
Default
setting
is
0.0.0.0
which
disables
this
function.
Interval:
This
sets
the
time
interval
between
Pings
to
the
IP
function
to
monitor
the
connection
status.
Default
interval
setting
is
10
seconds.
Time
interval
can
be
set
to
any
value
between
0
and
3600
seconds,
0
second
disables
this
function.
81
Chapter
4:
Configuration
Downloaded from
www.Manualslib.com
manuals search engine
Page 82 / 143
Billion 800VGT Router
Ping
to
the
IP
Interval
(sec)
Ping
to
the
IP
Action
0.0.0.0
0
No
0.0.0.0
2000
No
xxx.xxx.xxx.xxx
(Any
valid
IP
Address)
0
No
xxx.xxx.xxx.xxx(Any
valid
IP
Address)
2000
Yes,
activate
it
in
every
2000 second.
Disconnection
Time
after
no
traffic:
This
is
the
“NO
Response”
timer.
When
no
traffic
is
received
for
more
than
the
Disconnection
time
setting,
the
router
will
automatically
halt
the
tunnel
connection
and
re-establish
it
base
after
the
Reconnection
Time
has
elapsed.
180
seconds
is
minimum
time
interval
for this
function.
Reconnection
Time:
This
is
the
reconnecting
time
interval
after
the
NO
TRAFFIC
timeout
has
occurred.
3
minutes
is
minimum
time
interval
for
this
function.
Select
the
Apply
button
to
update
the
settings.
Example:
Configuring
a
IPSec
LAN-to-LAN
VPN
Connection
Table 3: Network Configuration and Security Plan
Branch
Office
Head
Office
Local
Network
ID
192.168.0.0/24
192.168.1.0/24
Local
Router
IP
69.1.121.30
69.1.121.3
Remote
Network
ID
192.168.1.0/24
192.168.0.0/24
Remote
Router
IP
69.1.121.3
69.1.121.30
IKE
Pre-shared
Key
12345678
12345678
VPN
Connection
Type
Tunnel
mode
Tunnel
mode
Security
Algorithm
ESP:MD5
with
AES
ESP:MD5
with
AES
Both
office
LAN
networks
MUST
on
different
subnets
when
using
the
LAN
to
LAN
application.
Attention
The
settings
of
Pre-shared
Key,
VPN
Connection
Type
and
Security
Algorithm
MUST
BE
identically
set
up
on
both
sides.
82
Chapter
4:
Configuration
Downloaded from
www.Manualslib.com
manuals search engine
Page 83 / 143
Billion 800VGT Router
Configuring
IPSec
VPN
in
the
Head
Office
1
2
3
4
5
Item
Function
Description
1
Connection
Name
IPSec_HeadOffice
Given
name
of
the
IPSec
connection
Subnet
Select
the
Subnet
button
IP
Address
192.168.1.0
2
Netmask
255.255.255.0
Head
office
network
3
Secure
Gateway
Address
(or
Hostname)
69.121.1.30
IP
address
of
the
head
office
router
(WAN
side)
Subnet
Select
the
Subnet
button
IP
Address
192.168.0.0
4
Netmask
255.255.255.0
Branch
office
network
ESP
Select
the
ESP
button
Authentication
MD5
Encryption
3DES
Prefer
Forward
Security
None
5
Pre-shared
Key
12345678
Security
plan
83
Chapter
4:
Configuration
Downloaded from
www.Manualslib.com
manuals search engine
Page 84 / 143
Billion 800VGT Router
Configuring
IPSec
VPN
in
the
Branch
Office
1
2
3
4
5
Item
Function
Description
1
Connection
Name
IPSec_Branch
Office
Given
name
of
the
IPSec
connection
Subnet
Select
the
Subnet
button
IP
Address
192.168.0.0
2
Netmask
255.255.255.0
Branch
office
network
3
Secure
Gateway
Address
(or
Hostname)
69.121.1.3
IP
address
of
the
head
office
router
(in
WAN
side)
Subnet
Select
the
Subnet
button
IP
Address
192.168.1.0
4
Netmask
255.255.255.0
Head
office
network
ESP
Select
the
ESP
button
Authentication
MD5
Encryption
3DES
Prefer
Forward
Security
None
5
Pre-shared
Key
12345678
Security
plan
84
Chapter
4:
Configuration
Downloaded from
www.Manualslib.com
manuals search engine
Page 85 / 143
Billion 800VGT Router
Example:
Configuring
a
IPSec
Host-to-LAN
VPN
Connection
85
Chapter
4:
Configuration
Downloaded from
www.Manualslib.com
manuals search engine

Rate

4.7 / 5 based on 3 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top