Subnet Mask
IP
ddress range entered above.
Enter the subnet mask corresponding to the
a
Tunnel Settings − IPSe
There are two methods for
required by IPSec − Manual Key entry and Internet Key Exchange (IKE).
The difference between Ma nd
SPI are determined. The Tu to
configure IKE for an IPSec VPN tunnel.
The differences between M
• For an IKE VPN PN
gateways. The
SPIs to maintain ion.
• Manual Key VPN requires the encryption key, authentication key
(if required), an
administrator w nection is configured.
An IKE VPN is generally c Manual Key VPN
ecause IKE can generate new keys and SPIs randomly during the
negotiation phase.
o configure an IPSec VPN using IKE, click the Tunnel Settings link to
c
exchanging the encryption/decryption keys
nual Key and IKE is how the encryption keys a
nnel Settings page on the DFL-600 allows you
anual Key and IKE can be summarized as:
, the keys and SPIs are negotiated between V
two VPN gateways can then use these keys and
the IPSec connect
d SPIs to be predetermined by a network
hen the IPSec con
onsidered more secure than a
b
T
open the page shown below.
The IPSEC Tunnel Mode page allows you to setup a secure tunnel between
your DFL-600 and a remote gateway.