![BinTec RS353j User Manual Download Page 359](http://html1.mh-extra.com/html/bintec/rs353j/rs353j_user-manual_2752938359.webp)
Field
Description
•
4(
(default value): If you do not use certific-
ates for the authentication, you can select Preshared Keys.
These are configured during peer configuration in the
VPN->IPSec->IPSec Peers. The preshared key is the shared
password.
•
53 #
: Phase 1 key calculations are authenticated
using the DSA algorithm.
•
@3 #
: Phase 1 key calculations are authenticated
using the RSA algorithm.
•
@3 %(+
: In RSA encryption the ID payload is also
encrypted for additional security.
Local Certificate
Only for Phase-1 (IKE) Parameters
Only for Authentication Method =
53 #
,
@3
#
or
@3 %(+
This field enables you to select one of your own certificates for
authentication. It shows the index number of this certificate and
the name under which it is saved. This field is only shown for
authentication settings based on certificates and indicates that a
certificate is essential.
Mode
Only for Phase-1 (IKE) Parameters
Select the phase 1 mode.
Possible values:
•
3##
(default value): The Aggressive Mode is neces-
sary if one of the peers does not have a static IP address and
preshared keys are used for authentication. It requires only
three messages to configure a secure channel.
•
' ' 5 %!
: This mode (also designated
Main Mode) requires six messages for a Diffie-Hellman key
calculation and thus for configuring a secure channel, over
which the IPSec SAs can be negotiated. A condition is that
both peers have static IP addresses if preshared keys are
used for authentication.
Also define whether the selected mode is used exclusively
(Strict), or the peer can also propose another mode.
bintec elmeg GmbH
16 VPN
bintec RS Series
345