Asentria SiteBoss 571 UserManual
Page 47
Phase 1 Hash
This is the phase 1 (IKE) hash algorithm to use (must be accommodated by IPsec peer). Options are MD5, or
SHA1
Phase 1 DH Group
This is the phase 1 DH group to use (must be accommodated by IPsec peer). Options are 2 or 5.
Phase 1 Life (seconds)
This defines how long in seconds before the IKE channel key should be renegotiated.
Phase 2 Encryption
This is the phase 2 encryption algorithm to use (must be accommodated by IPsec peer). Options are 3DES,
AES128, and AES 256.
Phase 2 Hash
This is the phase 2 (IKE) hash algorithm to use (must be accommodated by IPsec peer). Options are MD5, or
SHA1.
Phase 2 Life (seconds)
This defines how long in seconds before the tunnel key parameters should be renegotiated.
Dead Peer Detection Action
This controls what should be done when the phase 1 channel detects the peer to be longer present (dead). The
options are HOLD or RESTART.
Dead Peer Detection Period
This defines the period in seconds between keep alive transmissions for dead peer detection.
Dead Peer Detection Timeout
This defines how long in seconds of having an unacknowledged keep alive or no inbound keep alive from the other
peer after which the peer is detected to be no longer present.
Compression
This is an on/off toggle that controls whether or not to propose data compression to the peer.
PFS
This is an on/off toggle to enable or disabled perfect forward secrecy on the tunnel.
SSL Settings
Use this menu for
configuring the settings if the Mode is SSL Client or SSL Server.
SiteBoss 571 - VPN 2 SSL Settings
A) Protocol [UDP]
B) Port [1194]
C) Username []
D) Password [********]
E) Manual Configuration
Protocol
This toggles between UDP and TCP to set the protocol SSL VPN uses to carry VPN traffic. The default setting is
UDP.
Port
This sets what port (TCP or UDP, as determined by the SSL Protocol) the VPN uses. The default setting is 1194.
Username / Password
This sets the username and password that a VPN in SSL CLIENT mode uses when it connects to an OpenVPN
server. If the username is blank then the username "u<serial number>" will be used. E.g., "u5710009999" is the
username the unit sends to the OpenVPN server if this setting is blank and the SSL Password setting is not blank.