Robustel GoRugged R2000 User Guide
RT_UG_R2000_v.1.0.1 08.10.2015 47 /103
Confidential
When choose the “Tunnel Setting->Protocol” to “AH”.
SA Settings
Item
Description
Default
Encrypt Algorithm
Select from “3DES”, “AES128” and “AES256” when you select “ESP” in
“Protocol”;
Note: Higher security means more complex implementation and lower
speed. DES is enough to meet general requirements. Use 3DES when high
confidentiality and security are required.
3DES
Authentication
Algorithm
Select from “MD5” and “SHA1”to be used in SA negotiation.
MD5
PFS Group
Select from “PFS (N/A)”, “MODP (1024)” and
“
MODP (1536)”.
PFS (N/A): Disable PFS Group
MODP (1024): Uses the 1024-bit Diffie-Hellman group.
MODP (1536): Uses the 1536-bit Diffie-Hellman group.
MODP
(1024)
SA Lifetime
Set the IPSec SA lifetime.
Note: When negotiating to set up IPSec SAs, IKE uses the smaller one
between the lifetime set locally and the lifetime proposed by the peer.
28800
DPD Interval
Set the interval after which DPD is triggered if no IPSec protected packets is
received from the peer.
DPD: Dead peer detection. DPD irregularly detects dead IKE peers. When
60