Phase 1 advanced configuration – Billion Electric Company CO1 User Manual

Page 23

Advertising
background image

Billion BiGuard VPN Client

Chapter 4: VPN Configuration

20

z

AES: Stands for Advanced Encryption Standards, you can use 128, 192 or 256 bits as

encryption method.

~

IKE authentication

:

It is a Message Digest algorithm which coverts any length of a message

into a unique set of bits. It is widely used MD5 (Message Digest) and SHA (Secure Hash Algorithm)
algorithms.

SHA is more resistant to brute-force attacks than MD5, however it is slower.

z

MD5:

A one-way hashing algorithm that produces a 128−bit hash.

z

SHA:

A one-way hashing algorithm that produces a 160−bit hash.

~

IKE key group

(Diffie-Hellman key length)

:

It is a public-key cryptography protocol that

allows two parties to establish a shared secret over an unsecured communication channel (i.e. over
the Internet). There are three modes, MODP 768-bit, MODP 1024-bit and MODP 1536-bit. MODP
stands for Modular Exponentiation Groups.

For more advanced settings, click on

P1 Advanced

“.

Phase 1 Advanced configuration

For Advanced features and parameters, click on “P1 Advanced” button into Phase 1 panel.

Advanced features

~

Config Mode

:

If checked, the VPN Client will activate Config-Mode for this tunnel.

Config-Mode allows to the VPN Client to fetch some VPN Configuration information from
the VPN gateway like DNS/WINS server IP addresses. In case Config-Mode is not
available on the remote gateway, please refer to section “Phase2 Advanced” settings to
manually set DNS/WINS server addresses.

Advertising