Manual
Table Of Contents
- Chapter 1 Accessing the Web User Interface
- Chapter 2 Cellular Connections
- Chapter 3 Web User Interface
- 3.1 Web User Interface Introduction
- 3.2 Status Tab
- 3.3 Admin Tab
- 3.4 Network Tab
- 3.5 Services Tab
- 3.6 Automation Tab
- 3.7 Advanced Tab
- Chapter 4 Red Lion Support
- Chapter 5 Compliance Statements & User Information
- Chapter 6 Licensing & Warranty
- Chapter 7 Appendices

Software User Guide 81
Network Tab
Phase1DHGroup:SelecttheDHGroupneededforphase1(IKE)bychoosingoneofthevaluesfromthedrop‐down
listprovided.ThisoptionselectstheencryptionleveloftheDiffie‐HellmankeysandtheseareGroup1(768bits),
Group2(1024bits),Group5(1536bits)
orGr oup14(2048bits).Longerkeysimplybettersecuritybutatacostoflon‐
gernegotiation/set‐uptimeduringtheinitialconnectionestablishment.Thesesettingsmustmatchonbothendsof
theconnection.AvalueofNone
meansthatnoDHGroupwill beselectedforthisendofthetunnelanditwilladopt
thesettingsofitspeerduringconnectioninitiation.
Phase1ISAKMPTime(minutes):Selecthowlong,inminutes,thekeyingchannelofaconnection(ISAKMPSA)should
lastbeforebeingrenegotiated.
Pre‐Shared
Key(Required):Specifythekeytobeexchangedforencryptionnegotiationduringphase(IKE).Keymust
notcontainadouble‐quotecharacter.Note:ThePre‐SharedKeymustmatchonbothendsofthetunnelinorderto
work.
LocalPeerID:Specif y howtheleftparticipantshouldbeidentifiedfor
authentication.CanbeanIPaddressofafully
qualifieddomainnameprecededby@(whichisusedasaliteralstringandnotresolved).
RemotePeerID:Specif yhowtherightparticipantshouldbeidentifiedforauth entication.CanbeanIPaddressofa
fullyqualifieddomainnameprecededby
@(whichisusedasaliteralstringandnotresolved).
Phase2AuthType:DefineswhetherauthenticationshouldbedoneaspartofESPencryption,orseparatelyusingthe
AHprotocol.
Phase2Encryption:SelecttheESPencryptionalgorithmtobeusedfortheconnection.
Phase2Authentication:SelecttheESP
authenticationalgorithmtobeusedfortheconnection.
Phase2ISAKMPTime(minutes):Selecthowlong, inminutes,aparticularinstanceofaconnection(asetofencryp‐
tion/authenticationkeysforuserpackets)shouldlast,fromsuccessfulnegotiationtoexpiration.
• ClickontheNEXTbuttonandthefollowingTerminationSettingsdialog
windowwillappear:
LocalPublicIPAddress:ThisparametertypicallyonlyneedstobespecifiedwhentheRedLionrouterisconfiguredto
usemorethanoneexternal,untrustedinterface.SpecifytheIPAddressoftheleftparticipant’spublicnetworkinter‐
face.










