EasyManuals Logo

Draytek Vigor2925 Series User Manual

Draytek Vigor2925 Series
781 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #404 background imageLoading...
Page #404 background image
Vigor2925 Series User’s Guide
388
for the dial-in user to get IP from.
4
4
.
.
1
1
2
2
.
.
3
3
I
I
P
P
S
S
e
e
c
c
G
G
e
e
n
n
e
e
r
r
a
a
l
l
S
S
e
e
t
t
u
u
p
p
In IPSec General Setup, there are two major parts of configuration.
There are two phases of IPSec.
Phase 1: negotiation of IKE parameters including encryption, hash, Diffie-Hellman
parameter values, and lifetime to protect the following IKE exchange, authentication of
both peers using either a Pre-Shared Key or Digital Signature (x.509). The peer that
starts the negotiation proposes all its policies to the remote peer and then remote peer
tries to find a highest-priority match with its policies. Eventually to set up a secure tunnel
for IKE Phase 2.
Phase 2: negotiation IPSec security methods including Authentication Header (AH) or
Encapsulating Security Payload (ESP) for the following IKE exchange and mutual
examination of the secure tunnel establishment.
There are two encapsulation methods used in IPSec, Transport and Tunnel. The Transport
mode will add the AH/ESP payload and use original IP header to encapsulate the data payload
only. It can just apply to local packet, e.g., L2TP over IPSec. The Tunnel mode will not only
add the AH/ESP payload but also use a new IP header (Tunneled IP header) to encapsulate the
whole original IP packet.
Authentication Header (AH) provides data authentication and integrity for IP packets passed
between VPN peers. This is achieved by a keyed one-way hash function to the packet to create
a message digest. This digest will be put in the AH and transmitted along with packets. On the
receiving side, the peer will perform the same one-way hash on the packet and compare the
value with the one in the AH it receives.
Encapsulating Security Payload (ESP) is a security protocol that provides data confidentiality
and protection with optional authentication and replay detection service.

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Draytek Vigor2925 Series and is the answer not in the manual?

Draytek Vigor2925 Series Specifications

General IconGeneral
WAN Ports2 x Gigabit Ethernet
LAN Ports4 x Gigabit Ethernet
USB Ports2 x USB 2.0
VPN Tunnels50
Humidity10% to 90% non-condensing
VPN Throughput200 Mbps
Load BalancingYes
QoSYes
VPN ProtocolsIPSec, PPTP, L2TP, SSL
FirewallSPI
Power Supply12V DC
Operating Temperature0°C to 40°C
Storage Temperature-25°C to 70°C
WirelessOptional (with Vigor2925ac)

Related product manuals