G
ATEWAY
C
ONTROLLER
S
ERIES
U
SER
M
ANUAL
VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P
AGE
92
OF
135
Additional Proposals
If the other secure gateway rejects the proposals
configured above, the Controller can make additional
proposals as selected here.
Automatic Phase 2
Phase 2 of VPN is when the tunnel is constructed and traffic exchanged between the
secure networks as configured for that tunnel.
Protocol
The Controller uses the ESP protocol for VPN. Make sure
that this setting matches on the other VPN gateway.
Encryption
You can choose a faster DES encryption or slower 3DES.
3DES is more secure but require more resources.
Authentication
You can choose MD5 or SHA1. SHA1 is a little more secure.
Perfect Forward Secrecy
You can enable PFS to make the key generation a
little slower and more secure. You can select DH1 or DH2
as part of this process.
Additional Proposals
If the other secure gateway rejects the proposals
configured above, the Controller can make additional
proposals as selected here.
Key Timeout
The Controller phase 2 key timeout is 1 hour (3600
seconds). After this period, the Controller will request new
keys from the other gateway.
Manual Keying
Using Manual Keying, the encryption keys that secure the connection are provided to
each gateway and do not change.
Manual Phase 1
Using manual keys there is no phase 1 negotiation, the key is just sent.