Quick Reference Guide

Reference Manual for the Model FVS318 Broadband ProSafe VPN Firewall
Virtual Private Networking 6-15
M-10146-01
The IKE settings for each end point of the VPN tunnel must match exactly. To configure
the IKE settings, enter the following settings in each FVS318:
Enable Perfect Forward Secrecy.
For Encryption Protocol, select: DES.
Enter the Pre-Shared Key. In this example, enter r>T(h4&3@#kB as the Pre-Shared
Key. With IKE, a pre-shared key that you make up is used for mutual identification.
The Pre-Shared Key should be between 8 and 80 characters, and the letters are case
sensitive. Entering a combination of letters, numbers and symbols, such as
r>T(h4&3@#kB provides greater security.
Key Life - Default is 3600 seconds (1 hour)
IKE Life Time - Default is 28800 seconds (8 hours). A shorter time increases security,
but users will be temporarily disconnected upon renegotiation.
d. If you need to run Microsoft networking functions such as Network Neighborhood, click
the NETBIOS Enable check box to allow NETBIOS traffic over the VPN tunnel.
e. Click Apply to save the Security Association tunnel settings into the table.
3. Check the VPN Connection
To check the VPN Connection, you can initiate a request from one network to the other. If one
FVS318 has a dynamically assigned WAN IP address, you must initiate the request from that
FVS318’s network. The simplest method is to ping the LAN IP address of the other FVS318.
a. Using our example, from a PC attached to the FVS318 on LAN A, on the Windows
taskbar click the Start button, and then click Run.
b. Type ping -t 192.168.0.1 , and then click OK.
Figure 6-10: Running a Ping test from Windows