Cisco Small Business RV 120W Wireless-N VPN Firewall ...

Cisco Small Business RV 120W Wireless-N VPN Firewall ... Cisco Small Business RV 120W Wireless-N VPN Firewall ...

ipland.com.ua
from ipland.com.ua More from this publisher
12.07.2015 Views

Configuring Virtual Private Networks (VPNs) and SecurityConfiguring Advanced VPN Parameters5Manual Policy ParametersIf you chose manual as the policy type in Step 4, configure the manual policyparameters. The Manual Policy creates an SA (Security Association) based on thefollowing static inputs:SPI-Incoming, SPI-Outgoing—Enter a hexadecimal value between 3 and 8characters; for example, 0x1234.Encryption Algorithm—Select the algorithm used to encrypt the data.• Key-In—Enter the encryption key of the inbound policy. The length of thekey depends on the algorithm chosen:- DES—8 characters- 3DES—24 characters- AES-128—16 characters- AES-192—24 characters- AES-256—32 characters- AES-CCM—16 characters- AES-GCM—20 characters• Key-Out—Enter the encryption key of the outbound policy. The length of thekey depends on the algorithm chosen, as shown above.Integrity Algorithm—Select the algorithm used to verify the integrity of the data.• Key-In—Enter the integrity key (for ESP with Integrity-mode) for the inboundpolicy. The length of the key depends on the algorithm chosen:- MD5—16 characters- SHA-1— 20 characters- SHA2-256—32 characters- SHA2-384— 48 characters- SHA2-512—64 characters• Key-Out—Enter the integrity key (for ESP with Integrity-mode) for theoutbound policy. The length of the key depends on the algorithm chosen, asshown above.Cisco RV120W Administration Guide 101

Configuring Virtual Private Networks (VPNs) and SecurityConfiguring Advanced VPN Parameters5Manual Policy Example:Creating a VPN tunnel between two routers:Router 1: WAN1=10.0.0.1 LAN=192.168.1.1 Subnet=255.255.255.0Policy Name: manualVPNPolicy Type: Manual PolicyLocal Gateway: WAN1Remote Endpoint: 10.0.0.2Local IP: Subnet 192.168.1.0 255.255.255.0Remote IP: Subnet 192.168.2.0 255.255.255.0SPI-Incoming: 0x1111Encryption Algorithm: DESKey-In: 11112222Key-Out: 33334444SPI-Outgoing: 0x2222Integrity Algorithm: MD5Key-In: 1122334444332211Key-Out: 5566778888776655Router 2: WAN1=10.0.0.2 LAN=192.168.2.1 Subnet=255.255.255.0Policy Name: manualVPNPolicy Type: Manual PolicyLocal Gateway: WAN1Remote Endpoint: 10.0.0.1Local IP: Subnet 192.168.2.0 255.255.255.0Remote IP: Subnet 192.168.2.0 255.255.255.0SPI-Incoming: 0x2222Encryption Algorithm: DESKey-In: 33334444Key-Out: 11112222SPI-Outgoing: 0x1111Integrity Algorithm: MD5Key-In: 5566778888776655Key-Out: 1122334444332211Auto Policy ParametersIf you chose auto as the policy type in Step 4, configure the following:STEP 1SA Lifetime—Enter the duration of the Security Association and choose the unitfrom the drop-down list:• Seconds—Choose this option to measure the SA Lifetime in seconds. Afterthe specified number of seconds passes, the Security Association isrenegotiated. The default value is 3600 seconds. The minimum value is 300seconds.• Kbytes—Choose this option to measure the SA Lifetime in kilobytes. Afterthe specified number of kilobytes of data is transferred, the SA isrenegotiated. The minimum value is 1920000 KB.Cisco RV120W Administration Guide 102

Configuring Virtual Private Networks (<strong>VPN</strong>s) and SecurityConfiguring Advanced <strong>VPN</strong> Parameters5Manual Policy Example:Creating a <strong>VPN</strong> tunnel between two routers:Router 1: WAN1=10.0.0.1 LAN=192.168.1.1 Subnet=255.255.255.0Policy Name: manual<strong>VPN</strong>Policy Type: Manual PolicyLocal Gateway: WAN1Remote Endpoint: 10.0.0.2Local IP: Subnet 192.168.1.0 255.255.255.0Remote IP: Subnet 192.168.2.0 255.255.255.0SPI-Incoming: 0x1111Encryption Algorithm: DESKey-In: 11112222Key-Out: 33334444SPI-Outgoing: 0x2222Integrity Algorithm: MD5Key-In: 1122334444332211Key-Out: 5566778888776655Router 2: WAN1=10.0.0.2 LAN=192.168.2.1 Subnet=255.255.255.0Policy Name: manual<strong>VPN</strong>Policy Type: Manual PolicyLocal Gateway: WAN1Remote Endpoint: 10.0.0.1Local IP: Subnet 192.168.2.0 255.255.255.0Remote IP: Subnet 192.168.2.0 255.255.255.0SPI-Incoming: 0x2222Encryption Algorithm: DESKey-In: 33334444Key-Out: 11112222SPI-Outgoing: 0x1111Integrity Algorithm: MD5Key-In: 5566778888776655Key-Out: 1122334444332211Auto Policy ParametersIf you chose auto as the policy type in Step 4, configure the following:STEP 1SA Lifetime—Enter the duration of the Security Association and choose the unitfrom the drop-down list:• Seconds—Choose this option to measure the SA Lifetime in seconds. Afterthe specified number of seconds passes, the Security Association isrenegotiated. The default value is 3600 seconds. The minimum value is 300seconds.• Kbytes—Choose this option to measure the SA Lifetime in kilobytes. Afterthe specified number of kilobytes of data is transferred, the SA isrenegotiated. The minimum value is 1920000 KB.<strong>Cisco</strong> <strong>RV</strong><strong>120W</strong> Administration Guide 102

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!