HP SuperStack Firewall Series Manual do Utilizador Página 128

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
Vista de página 127
128 C
HAPTER
9: C
ONFIGURING
V
IRTUAL
P
RIVATE
N
ETWORK
S
ERVICES
Leave the Disable all Windows Networking (NetBIOS) Broadcasts box
unchecked for the Enable Windows Networking (NetBIOS) broadcast
settingtohaveeffect.SeeDisable all Windows Networking (NetBIOS)
Broadcastson page 124 for details.
Enable Perfect Forward Secrecy
Check the Enable Perfect Forward Secrecy check box to change
encryption keys during the second stage of VPN negotiation. This feature
blocks intruders from decrypting keys by brute force but extends VPN
negotiation time.
This setting is not available if the IPSec Keying Mode is set to Manual Key.
SA Life time (secs)
The SA Life time (secs) field allows you to specify the number of seconds
you want a Security Association to last before new encryption and
authentication keys must be exchanged.
As the connection is temporarily disabled when the keys are
renegotiated, a low value (short time) will increase security but may cause
inconvenience. The default value for the SA Life time (secs) field is
28800 seconds (8 hours).
Enter the number 28800 or your desired value.
This setting is not available if the IPSec Keying Mode is set to Manual Key.
Incoming SPI and Outgoing SPI
The Incoming Security Parameter Index (SPI) and Outgoing SPI are two
eight digit hexadecimal numbers that identify the Security Association
used for the VPN Tunnel. The Incoming SPI and Outgoing SPI for a SA can
be the same but must differ for all other SPIs used on your network
Additionally the values from 00000000 to 000000FF have been reserved
by the Internet Engineering Task Force (IETF) and are not allowed for use
as an SPI.
Enter your chosen Incoming SPI and Outgoing SPI in the relevant fields.
If you enter less than eight hexadecimal digits the SPI will be padded with
leading zeros. For example SPIs of F00and 00000F00will be treated
as equivalent.
DUA1611-0AAA02.book Page 128 Thursday, August 2, 2001 4:01 PM
Vista de página 127
1 2 ... 123 124 125 126 127 128 129 130 131 132 133 ... 213 214

Comentários a estes Manuais

Sem comentários