Netgear FVS328 참조 매뉴얼

다운로드
페이지 228
Model FVS328 ProSafe VPN Firewall with Dial Back-up Reference Manual
7-2
Virtual Private Networking
May 2004, 202-10031-01
IKE Policies: Define the authentication scheme and automatically generate the encryption 
keys. As an alternative option, to further automate the process, you can create an Internet Key 
Exchange (IKE) policy which uses a trusted certificate authority to provide the authentication 
while the IKE policy still handles the encryption.
VPN Policies: Apply the IKE policy to specific traffic which requires a VPN tunnel. Or, you 
can create a VPN policy which does not use an IKE policy but in which you manually enter all 
the authentication and key parameters.
Since the VPN Auto policies require IKE policies, you must define the IKE policy first. The 
FVS328 also allows you to manually input the authentication scheme and encryption key values. 
VPN Manual policies manage the keys according to settings you select and do not use IKE 
policies.  
In order to establish secure communication over the Internet with the remote site you need to 
configure matching VPN parameters on both the local and remote sites. The outbound VPN 
parameters on one end must match to the inbound VPN parameters on other end, and vice versa.
When the network traffic enters into the FVS328 from the LAN network interface, if there is no 
VPN policy found for a type of network traffic, then that traffic passes through without any 
change. However, if the traffic is selected by a VPN policy, then the Internet Protocol security 
IPSec authentication and encryption rules will be applied to it as defined in the VPN policy.
By default, a new VPN policy is added with the least priority, that is, at the end of the VPN policy 
table. You can change the priority by selecting the VPN policy from the policy table and clicking 
Move.
Using Automatic Key Management
The most common configuration scenarios will use IKE policies to automatically manage the 
authentication and encryption keys. Based on the IKE policy, some parameters for the VPN tunnel 
are generated automatically. The IKE protocols perform negotiations between the two VPN 
endpoints to automatically generate required parameters. 
Some organizations will use an IKE policy with a Certificate Authority (CA) to perform 
authentication. Typically, CA authentication is used in large organizations which maintain their 
own internal CA server. This requires that each VPN gateway have a certificate and trust 
certificate root from the CA. Using CAs reduces the amount of data entry required on each VPN 
endpoint.