Field
Description
• Input in Seconds: Enter the lifetime for phase 1 key in
seconds. The value can be a whole number from 0 to
2147483647. The default value is
, which means the
key must be renewed once four hours have elapsed.
• Input in kBytes: Enter the lifetime for phase 1 keys as amount
of data processed in kBytes. The value can be a whole num-
ber from 0 to 2147483647. The default value is
, which
means that the number of transmitted kBytes is irrelevant.
Authentication Method Only for Phase-1 (IKE) Parameters
Select the authentication method.
Possible values:
•
! =0
(default value): If you do not use certific-
ates for the authentication, you can select Preshared Keys.
These are configured during peer configuration in the
VPN->IPSec->IPSec Peers. The preshared key is the shared
password.
•
-, 3
: Phase 1 key calculations are authenticated
using the DSA algorithm.
•
?, 3
: Phase 1 key calculations are authenticated
using the RSA algorithm.
•
?, *0
: In RSA encryption the ID payload is also
encrypted for additional security.
Local Certificate
Only for Phase-1 (IKE) Parameters
Only for Authentication Method =
-, 3
,
?,
3
or
?, *0
This field enables you to select one of your own certificates for
authentication. It shows the index number of this certificate and
the name under which it is saved. This field is only shown for
authentication settings based on certificates and indicates that a
certificate is essential.
Mode
Only for Phase-1 (IKE) Parameters
Select the phase 1 mode.
Possible values:
bintec elmeg GmbH
14 VPN
be.IP 4isdn
255