User's Manual
[ pg. 80]
• Perfect Forward Secrecy: Select Enable or Disable to enable or disable PFS (Perfect Forward Secrecy). PFS is an additional security protocol.
• DH Group: Select a PFS DH Group from the drop-down menu (Group 1, Group 2, Group 5, Group 14). As the DH Group number increases, the
higher the level of encryption implemented for PFS.
•
Life Time:
Enter the number of seconds for the IPSec Lifetime. The period of time to pass before establishing a new IPSec security association
(SA) with the remote endpoint. The default value is 28800.
Network
• Security Gateway Type: Security Gateway Type supports IP Address and
Domain Name. Select one of them.
• Security Gateway: The IP address or domain name of the VPN server.
• Local Network: Enter the local (LAN) subnet and mask. (ex.
192.168.0.0/255.255.255.0)
• Remote Network: Enter the remote subnet and mask. (ex.
192.168.9.0/255.255.255.0)
Advanced
• NAT Traversal: Enabling NAT Traversal allow IPSec traffic from this
endpoint to traverse through the translation process during NAT. The
remote VPN endpoint must also support this feature and it must be
enabled to function properly over the VPN.
• Dead Peer Detection: Enable DPD (Dead Peer Detection) to delete the
VPN tunnel if there is no traffic detected. The VPN will re-establish once traffic is again sent through the tunnel.
Click Apply to save the IPSec VPN profile setting.