26
Chapter 5: Configuring the Gateway
The Security Tab
ADSL2 Gateway with 4-Port Switch
•
Key Life Time. In the Key Lifetime field, you may optionally select to have the key expire at the end of a time
period of your choosing.
Enter the number of seconds you’d like the key to be used until a re-key negotiation
between each endpoint is completed.
Phase 2
•
Encryption. The encryption method selected in Phase 1 will be displayed.
•
Authentication. The authentication method selected in Phase 1 will be displayed.
•
PFS. The status of PFS will be displayed.
•
Group. There are two Diffie-Hellman Groups to choose from: 768-bit and 1024-bit. Diffie-Hellman refers to a
cryptographic technique that uses public and private keys for encryption and decryption.
•
Key Life Time. In the Key Lifetime field, you may select to have the key expire at the end of a time period of
your choosing.
Enter the number of seconds you’d like the key to be used until a re-key negotiation between
each endpoint is completed.
Other Setting
•
NetBIOS broadcast. Check the box next to NetBIOS broadcast to enable NetBIOS traffic to pass through the
VPN tunnel.
•
Anti-replay. Check the box next to Anti-replay to enable the Anti-replay protection. This feature keeps track of
sequence numbers as packets arrive, ensuring security at the IP packet-level.
•
Keep-Alive. If you select this option, the Gateway will periodically check your Internet connection. If you are
disconnected, then the Gateway will automatically re-establish your connection.
•
Check this box to block unauthorized IP addresses. Enter in the field to specify how many times IKE must fail
before blocking that unauthorized IP address. Enter the length of time that you specify (in seconds) in the
field.
When finished making your changes on this tab, click the
Save Settings
button to save these changes, or click
the
Cancel Changes
button to undo your changes. For further help on this tab, click the
Help
button.
Figure 5-19: Advanced VPN Tunnel Setup