Virtual Private Networks (VPN)
IPsec
IX14 User Guide
551
j. Configure the types of encryption, hash, and Diffie-Hellman group to use during phase 2:
i. Move back two levels in the schema:
(config vpn ipsec tunnel ipsec_example ike phase1_proposal 0)> ..
..
(config vpn ipsec tunnel ipsec_example ike)>
ii. Add a phase 2 proposal:
(config vpn ipsec tunnel ipsec_example ike)> add ike phase2_
proposal end
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)>
iii. Set the type of encryption to use during phase 2:
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)>
cipher
value
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)>
where
value
is one of
3des
,
aes128
,
aes192
,
aes256
, or
null
. The default is
3des
.
iv. Set the type of hash to use during phase 2 to verify communication integrity:
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)>
hash
value
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)>
where
value
is one of
md5
,
sha1
,
sha256
,
sha384
, or
sha512
. The default is
sha1
.
v. Set the type of Diffie-Hellman group to use for key exchange during phase 2:
i. Use the
?
to determine available Diffie-Hellman group types:
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)>
dh_group ?
curve25519
curve448
ecp192
ecp224
...
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)>
ii. Set the Diffie-Hellman group type:
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)>
dh_group
value
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)>
The default is
modp2048
.
vi. (Optional) Add additional phase 2 proposals: