G
ATEWAY
C
ONTROLLER
S
ERIES
U
SER
M
ANUAL
2011, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P
AGE
89
OF
124
Manual Phase 2
Protocol
The Controller uses the ESP protocol for VPN. Make sure
that this setting matches on the other VPN gateway.
Encryption
You can choose a faster DES encryption or slower 3DES.
3DES is more secure but require more resources.
Authentication
You can choose MD5 or SHA1. SHA1 is a little more
secure.
Security Parameter Index
You must enter a hexadecimal value between 100
and FFF. This is used to identify the tunnel. The
Controller uses the same SPI for incoming and outgoing
tunnels. This value must match the setting on the other
gateway.
Encryption Key
You must enter a hexadecimal value of the following
length:
DES: 16
3DES: 48
Authentication Key
You must enter a hexadecimal value of the following
length:
MD5: 32
SHA1: 40
Note: The other gateway may accept ASCII (2 byte) values for manual keys and convert
them to hex, so make sure you account for this in matching the keys. Contact the vendor if
you are not able to determine the actual HEX key generated from the ASCII value, as they
may be hashing it or doing some other transformation.
Monitoring VPN Tunnels
You can check the status of the VPN tunnels under System Status – VPN Tunnels.
Click on VPN Log to see a more detailed log of VPN activity.