Linksys RV042 Network Router User Manual


 
Chapter 4
Advanced Configuration
38
10/100 4-Port VPN Router
Remote Security Gateway Type > Dynamic IP + Domain Name(FQDN)
Authentication
Domain Name Enter the domain name for authentication.
(Once used, you cannot use it again to create a new tunnel
connection.)
Dynamic IP + E-mail Addr.(USER FQDN) Authentication
The Remote Security Gateway will be a dynamic IP
address, so you do not need to enter the IP address. When
the Remote Security Gateway requests to create a tunnel
with the Router, the Router will work as a responder.
Remote Security Gateway Type > Dynamic IP + E-mail Addr.(USER
FQDN) Authentication
E-mail address Enter the e-mail address for
authentication.
Remote Security Group Type
Select the Remote Security Group behind the Remote
Gateway that can use this VPN tunnel. Select the type
you want to use: IP, Subnet, or IP Range. Follow the
instructions for the type you want to use.
NOTE: The Remote Security Group Type you
select should match the Local Security Group
Type selected on the VPN device at the other
end of the tunnel.
After you have selected the Remote Security Group
Type, the settings available on this screen may change,
depending on which selection you have made.
IP
Only the computer with a specific IP address will be able
to access the tunnel.
Remote Security Group Type > IP
IP address Enter the appropriate IP address.
Subnet
The default is Subnet. All computers on the remote subnet
will be able to access the tunnel.
Remote Security Group Type > Subnet
IP address Enter the IP address.
Subnet Mask Enter the subnet mask. The default is
255.255.255.0.
IP Range
Specify a range of IP addresses within a subnet that will be
able to access the tunnel.
Remote Security Group Type > IP Range
IP range Enter the range of IP addresses.
IPSec Setup
In order for any encryption to occur, the two ends of a
VPN tunnel must agree on the methods of encryption,
decryption, and authentication. This is done by sharing
a key to the encryption code. For key management, the
default mode is IKE with Preshared Key.
Keying Mode Select IKE with Preshared Key or Manual.
Both ends of a VPN tunnel must use the same mode of
key management. After you have selected the mode, the
settings available on this screen may change, depending
on the selection you have made. Follow the instructions
for the mode you want to use.
IKE with Preshared Key
IKE is an Internet Key Exchange protocol used to negotiate
key material for Security Association (SA). IKE uses the
Preshared Key to authenticate the remote IKE peer.
Phase 1 DH Group Phase 1 is used to create the SA. DH
(Diffie-Hellman) is a key exchange protocol used during
Phase 1 of the authentication process to establish pre-
shared keys. There are three groups of different prime
key lengths. Group 1 is 768 bits, and Group 2 is 1,024 bits.
Group 5 is 1,536 bits. If network speed is preferred, select
Group 1. If network security is preferred, select Group 5.
Phase 1 Encryption Select a method of encryption: DES
(56-bit), 3DES (168-bit), AES-128 (128-bit), AES-192 (192-
bit), or AES-256 (256-bit). The method determines the
length of the key used to encrypt or decrypt ESP packets.
AES-256 is recommended because it is the most secure.
Make sure both ends of the VPN tunnel use the same
encryption method.
Phase 1 Authentication Select a method of
authentication, MD5 or SHA. The authentication method
determines how the ESP packets are validated. MD5 is