Configuring VPN
Managing Certificates
Cisco CVR100W Wireless-N VPN Router Administration Guide 111
6
STEP 4 Click Save. Then click Back to return to the Advanced VPN Setup page.
STEP 5 Click IPSec Connection Status to see the status of all site-to-site VPN policies on
the CVR100W.
Managing Certificates
The CVR100W uses digital certificates for IPsec VPN authentication and SSL
validation (for HTTPS). You can generate and sign your own certificates using
functionality available on the CVR100W.
Generating a New Certificate
You can generate a new certificate to replace the existing certificate on the
CVR100W.
To generate a certificate:
STEP 1 Choose VPN > Certificate Management.
STEP 2 Click the Generate a New Certificate radio button.
STEP 3 Click Generate Certificate.
Integrity Algorithm Select the algorithm used to verify the integrity of the
data.
PFS Key Group Check Enable to enable Perfect Forward Secrecy
(PFS) to improve security. While slower, this protocol
helps to prevent intruders by ensuring that a Diffie-
Hellman exchange is performed for every phase-2
negotiation.
Select IKE Policy Choose the IKE policy that will define the
characteristics of phase 1 of the negotiation. Click
View to view or edit the existing IKE policy that is
configured on the CVR100W.