Watchguard Wireless Router User's Guide Page 159

  • Download
  • Add to my manuals
  • Print
  • Page
    / 254
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 158
Manual VPN: Setting Up Manual VPN Tunnels
User Guide 145
N
OTE
N
OTE
If your Edges external interface has a private IP address instead of
a public IP address, then your ISP or the Internet access device
connected to the Edge’s external interface (modem or router) does
Network Address Translation (NAT). See the instructions at the end
of this section if your Edge’s external interface has a private IP
address.
3 Select the type of authentication from the Authentication
Algorithm drop-down list.
The options are MD5-HMAC (128-bit authentication) or SHA1-HMAC
(160-bit authentication).
4 From the Encryption Algorithm drop-down list, select the type
of encryption.
The options are DES-CBC or 3DES-CBC.
5 Type the number of kilobytes and the number of hours until the
IKE negotiation expires.
To make the negotiation not expire, enter zero. For example, 24 hours
and zero kilobytes means that the phase 1 key is negotiated every 24
hours.
6 Select the group number from the Diffie-Hellman Group drop-
down list. WatchGuard supports group 1 and group 2.
Diffie-Hellman groups securely negotiate secret keys through a public
network. Group 2 is more secure than group 1, but uses more processing
power and more time.
7 Select the Generate IKE Keep Alive Messages check box to help
find when the tunnel is down.
Select this check box to send short packets across the tunnel at regular
intervals. This helps the two devices to see if the tunnel is up. If the Keep
Alive packets get no response after three tries, the Firebox X Edge starts
the tunnel again.
N
OTE
N
OTE
The IKE Keep Alive feature is different from the VPN Keep Alive
feature in “VPN Keep Alive,” on page 148.
If your Firebox X Edge is behind a device that does
Network Address Translation (NAT)
The Firebox X Edge can use NAT-Traversal. This means that you can
make VPN tunnels if your ISP does Network Address Translation
(NAT) or if your Edge’s external interface is connected to a device
that does NAT. We recommend that the Edge’s external interface
Page view 158
1 2 ... 154 155 156 157 158 159 160 161 162 163 164 ... 253 254

Comments to this Manuals

No comments