G
ATEWAY
C
ONTROLLER
S
ERIES
U
SER
M
ANUAL
VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P
AGE
91
OF
135
Automatic Keying
Using
Automatic Keying
, the encryption keys that secure the connection are
constantly changed. This makes the process much more complicated, but also very
secure. It is critical that all the settings match between the two VPN gateways, or
they will not connect. You can generally pick a more or less secure option for each
step. The more secure option will result in slower connections and more processing
overhead, which may affect nonsecure connections by subscribers.
Automatic Phase 1
Phase 1 of VPN is when the two sides identify each other as legitimate VPN gateways
and agree on how to establish the connection.
Mode
You can choose a longer version of the initial contact
process, IKE Main, or a shorter version, IKE Aggressive.
Pre-shared Key
This is the initial key used to establish the connection.
Afterwards new keys are automatically generated.
Encryption
You can choose a faster DES encryption or slower 3DES.
3DES is more secure but require more resources.
Authentication
You can choose MD5 or SHA1. SHA1 is a little more secure.
DH Group
You can choose a shorter DH1 or longer DH2.
Key Timeout
The Controller phase 1 key timeout is 6 hours (21600
seconds on some gateways). After this period, the
Controller will request new keys from the other gateway.