SMARTRG INC. PROPRIETARY AND CONFIDENTIAL. ALL RIGHTS RESERVED. COPYRIGHT © 2016
94
Field Name
Description
l
Disable
: Permits long-term keys to be compromised.
Advanced IKE Settings
You can configure advanced IKE settings if desired.
1. On the IPSec Settings page, click
Show Advanced IKE Settings
to display the Phase 1 and Phase 2 fields.
2. Fill in the fields, using the information in the table below.
Field Name
Description
Mode
Select a mode. Options are
Main
and
Aggressive
.
Encryption Algorithm
Select the encryption algorithm. Options are
3DES
,
AES -
128
,
AES-192
, and
AES-256
.
Integrity Algorithm
Select the integrity algorithm. Options are
MD5
and
SHA1
.
Select Diffie-Hellman Group for
Key Exchange
Select the D-H group. Options are
768bit
-
8192bit
. The
default is
1024bit
.
Key Life Time
Enter the number of seconds that a key is valid. The default
is
3600
seconds.
3. Click
Apply/Save
to commit your changes.
Certificate
On this page, you can configure certificates for the gateway. You can use Local and Trusted CA certificates on this gateway.
Local
Local certificates are used to identify the gateway to other users. On this page, you can create a new certificate request locally and have
it signed by a certificate authority, or you can import an existing certificate.
For additional info regarding Public Key Infrastructure (PKI), refer to ITU-T X.509.
1. In the left navigation bar, click
Advanced Setup
>
Certificate
>
Local
and then click
Create Certificate Request
. The following
page appears.