EasyManua.ls Logo

ZyXEL Communications P-660HN-51 - Configuring Manual Key

ZyXEL Communications P-660HN-51
310 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Chapter 13 IPSec
P-660HN-51 User’s Guide
154
13.2.1.2 Manual Key Setup
Manual key management is useful if you have problems with Auto(IKE) key management.
13.2.1.3 Security Parameter Index (SPI)
An SPI is used to distinguish different SAs terminating at the same destination and using the same IPSec
protocol. This data allows for the multiplexing of SAs to a single gateway. The SPI (Security Parameter
Index) along with a destination IP address uniquely identify a particular Security Association (SA). The SPI
is transmitted from the remote VPN gateway to the local VPN gateway. The local VPN gateway then
uses the network, encryption and key values that the administrator associated with the SPI to establish
the tunnel.
Current Zyxel implementation assumes identical outgoing and incoming SPIs.
13.2.2 Configuring Manual Key
You only configure VPN manual key when you select Manual in the Key Exchange Method field on the
IPSec > Setting: Add/Edit screen. The following is the IPSec Setting - Manual screen.
Key Life Time
(Seconds)
Define the length of time before an IKE or IPSec SA automatically renegotiates in
this field. It may range from 1 to 2,000,000,000 seconds.
A short SA Life Time increases security by forcing the two VPN gateways to update
the encryption and authentication keys. However, every time the VPN tunnel
renegotiates, all users accessing remote resources are temporarily disconnected.
Apply/Save Click Apply/Save to save your changes and return to the IPSec screen.
Cancel Click Cancel to exit this screen without saving.
Table 55 Settings > Add/Edit: Auto(IKE) (continued)
LABEL DESCRIPTION

Table of Contents

Other manuals for ZyXEL Communications P-660HN-51

Related product manuals