Netgear SRX5308 Specifications Page 162

  • Download
  • Add to my manuals
  • Print
  • Page
    / 357
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 161
Virtual Private Networking Using IPSec Connections
162
ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
3. Complete the settings as explained the following table.
Table 38. Add IKE Policy screen settings
Setting Description
Mode Config Record
Do you want to use
Mode Config Record?
Specify whether or not the IKE policy uses a Mode Config record. For information
about how to define a Mode Config record, see Mode Config Operation on
page 176. Select one of the following radio buttons:
Yes. IP addresses are assigned to remote VPN clients. You need to select a
Mode Config record from the drop-down list.
No. Disables Mode Config for this IKE policy.
Note: Because Mode Config functions only in Aggressive mode, selecting the
Yes radio button sets the tunnel exchange mode to Aggressive mode and
disables the Main mode. Mode Config also requires that both the local and remote
ends are defined by their FQDNs.
Note: An XAUTH configuration via an edge device is not possible without Mode
Config and is therefore disabled too. For more information about XAUTH, see
Configure Extended Authentication (XAUTH) on page 172.
Select Mode
Config Record
From the drop-down list, select one of the Mode Config
records that you defined on the Add Mode Config Record
screen (see Configure Mode Config Operation on the VPN
Firewall on page 177).
Note: Click the View Selected button to open the Selected
Mode Config Record Details popup window.
General
Policy Name A descriptive name of the IKE policy for identification and management purposes.
Note: The name is not supplied to the remote VPN endpoint.
Direction / Type From the drop-down list, select the connection method for the VPN firewall:
Initiator. The VPN firewall initiates the connection to the remote endpoint.
Responder. The VPN firewall responds only to an IKE request from the remote
endpoint.
Both. The VPN firewall can both initiate a connection to the remote endpoint
and respond to an IKE request from the remote endpoint.
Exchange Mode From the drop-down list, select the exchange mode between the VPN firewall and
the remote VPN endpoint:
Main. This mode is slower than the Aggressive mode but more secure.
Aggressive. This mode is faster than the Main mode but less secure.
Note: If you specify either an FQDN or a User FQDN name as the local ID or
remote ID (see the Local and Remote sections on the screen), the Aggressive
mode is automatically selected.
Page view 161
1 2 ... 157 158 159 160 161 162 163 164 165 166 167 ... 356 357

Comments to this Manuals

No comments