
252 Chapter 13 VPN
NN47923-500
VPN Client Termination IP pool summary
In the WebGUI, click VPN on the navigation panel and the Client Termination
tab to open the VPN Client Termination screen. Then click the Configure IP
Address Pool link to open the screen in Figure 79. Use this screen to manage the
list of ranges of IP addresses to assign to the Contivity VPN clients.
IP Address Pool Have the Business Secure Router assign IP addresses to the
Contivity VPN clients from a pool of IP address that you define.
Select the pool to use. Click Configure IP Address Pool to
define the ranges of IP addresses that you can select from.
Enable Perfect
Forward Secrecy
Perfect Forward Secrecy (PFS) is disabled by default in phase 2
IPSec SA setup. This allows faster IPSec setup, but is not so
secure. Turn on PFS to use the Diffie-Hellman exchange to create
a new key for each IPSec SA setup.
Rekey Timeout Set the allowed lifetime for an individual key used for data
encryption before negotiating a new key. A setting of 00:00:00
disables the rekey timeout.
Rekey Data Count Set how much data can be transmitted through the VPN tunnel
before negotiating a new key. A setting of 0 disables the rekey
data count.
Advanced Click Advanced to configure detailed VPN client tunnel
termination settings.
Apply Click Apply to save your changes to the Business Secure Router.
Reset Click Reset to begin configuring this screen afresh.
Table 60 VPN Client Termination
Label Description
Commentaires sur ces manuels