Page 31 / 155 Scroll up to view Page 26 - 30
31
Using the Configuration Menu
Home > VPN Settings > Tunnel > Manual
Remote Subnet
The subnet of the remote VPN gateway’s local network. It
can be a host, a partial subnet, or a whole subnet.
Remote Netmask
The subnet of the remote VPN gateway’s local network.
It can be a host, a partial subnet, or a whole subnet.
Remote Gateway
The WAN IP address of remote VPN gateway.
Local Subnet
The subnet of the VPN gateway’s local network. It can be a
host, a partial subnet, or a whole subnet.
Local Netmask
Local netmask combined with local subnet to form a subnet
domain.
Aggressive Mode
Enabling this mode will accelerate establishing tunnel, but
the device will have less security.
Tunnel Name
Current tunnel name.
Remote SPI
The value of the remote SPI should be set in hex format.
Local SPI
The value of the local SPI should be set in hex format.
Method
The set of rules applied when connecting to the VPN gateway.
Page 32 / 155
32
Using the Configuration Menu
Home > VPN Settings > Tunnel > Manual
Continued...
Encapsulation
Protocol
There are two protocols that can be selected: ESP and AH.
Encryption
Algorithm
There are two algorithms that can be selected: 3DES and DES.
Authentication
Algorithm
There are two algorithms that can be selected: SHA1 and MD5.
Encryption Key
For DES, the encryption key is 8 bytes (16 Char.). For 3DES,
the encryption key is
24 bytes (48 Char.).
Authentication Key
For MD5, the authentication algorithm is16 bytes (32 Char.).
For SHA1, the authentication algorithm is 20 bytes.(40 Char.).
Life Time
Enter in the life time value.
Life Time Unit
There are two units that can be selected: Second and KB.
Page 33 / 155
33
Home > VPN Settings > Dynamic VPN Tunnel
Using the Configuration Menu
Local Subnet
The subnet of the VPN gateway’s local network. It can be a
host, a partial subnet, or a whole subnet.
Local Netmask
The netmask of the VPN gateway’s local network.
Aggressive Mode
Enabling this mode will accelerate establishing the tunnel,
but the device will have less security.
Tunnel Name
Current tunnel name.
This feature works with a VPN software client so the DI-
824VUP+ does not need to know the IP address of the re-
mote clients.
Dynamic VPN
There are three parts that are necessary to setup the
configuration of IKE for the dedicated tunnel: basic setup, IKE
proposal setup, and IPSec proposal setup. Basic setup
includes the setting of following items: local subnet, local
netmask, remote subnet, remote netmask, remote gateway,
and pre-shared key. The tunnel name is derived from the previous
page of VPN setting. IKE proposal setup includes the setting
of a set of frequent-used IKE proposals and selecting from the
set of IKE proposals.
VPN Settings - IKE
Page 34 / 155
34
Using the Configuration Menu
Home > VPN Settings > Dynamic VPN Tunnel
Continued...
Preshared Key
The first key that supports IKE mechanism of both VPN
gateways for negotiating further security keys. The pre-
shared key must be the same for both endpoint gateways.
IKE Proposal index
Click the button to setup a set of frequent-used IKE
proposals and select from the set of IKE proposals for the
dedicated tunnel.
IPSec Proposal
index
Click the button to setup a set of frequent-used IPSec
proposals and select from the set of IKE proposals for the
dedicated tunnel.
Page 35 / 155
35
Using the Configuration Menu
Home > VPN Settings > Dynamic VPN Tunnel > Set IKE Proposal
IKE Proposal index
Proposal Name
DH Group
Encrypt algorithm
Auth algorithm
A list of selected proposal indexes from the IKE proposal
pool listed below.
There are three groups that can be selected: group 1
(MODP768), group 2 (MODP1024), and group 5 (MODP1536).
There are two algorithms that can be selected: 3DES and
DES.
It indicates which IKE proposal to be focused.
There are two algorithms that can be selected: SHA1 and
MD5.

Rate

4.5 / 5 based on 2 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top