Trendnet TW100-BRV204 User Manual

Page of 123
TW100-BRV204 User Guide 
78 
IKE Phase 1 
If you selected IKE, the following screen is displayed after the Traffic Selector screen. 
 
Figure 52: VPN Wizard - IKE Phase 1 
IKE Phase 1 (IKE SA) 
Direction 
Select the desired option: 
•  Initiator - Only outgoing connections will be created. Incoming 
connection attempts will be rejected. 
•  Responder - Only incoming connections will be accepted. 
Outgoing traffic which would otherwise result in a connection 
will be ignored. 
•  Both Directions - Both incoming and outgoing connections are 
allowed. 
Local Identity 
This setting must match the "Remote Identity" on the remote VPN. 
IP address is the more common method. 
Remote Identity 
This setting must match the "Local Identity" on the remote VPN.  
IP address is the more common method. 
Authentication 
 
•  RSA Signature requires that both VPN endpoints have valid 
Certificates issued by a CA (Certification Authority). 
•  For Pre-shared key, enter the same key value in both endpoints. 
The key should be at least 8 characters (maximum is 128 charac-
ters). Note that this key is used for the IKE SA only. The keys 
used for the IPsec SA are automatically generated. 
Encryption 
Select the desired method, and ensure the remote VPN endpoint uses 
the same method.  The "3DES" algorithm provides greater security 
than "DES", but is slower. 
IKE Exchange 
Mode 
Select the desired option, and ensure the remote VPN endpoint uses 
the same mode. Main Mode provides identity protection for the hosts 
initiating the IPSec session, but takes slightly longer to complete. 
Aggressive Mode provides no identity protection, but is quicker.