Configuring VPN and Security
Configuring Advanced VPN Parameters
STEP 4
Cisco RV180/RV180W Administration Guide
•
DER ASN1 DN
If you chose FQDN, User-FQDN, or DER ASN1 DN as the identifier type—
Enter the IP address or domain name in the Identifier field.
In the IKE SA Parameters section, enter these settings:
The Security Association (SA) parameters define the strength and mode for
negotiating the SA.
•
Encryption Algorithm—Choose the algorithm used to negotiate the SA:
-
DES
-
3DES
-
AES-128
-
AES-192
-
AES-256
•
Authentication Algorithm—Specify the authentication algorithm for the
VPN header:
-
MD5
-
SHA-1
-
SHA2-256
-
SHA2-384
-
SHA2-512
Ensure that the authentication algorithm is configured identically on both
sides.
•
Authentication Method—Choose one of the following options:
-
Pre-Shared Key—Choose this option for a simple password-based key
that is shared with the IKE peer. Then enter the key in the space provided.
Note that the double-quote character (") is not supported in the pre-
shared key.
-
RSA-Signature—Choose this option to disable the pre-shared key text
field and use the Active Self Certificate that was uploaded on the
Security > SSL Certificate page. A certificate must be configured in
order for RSA-Signature to work.
5
114