Field
Description
Hash algorithms (Authentication):
•
.-
: MD5 (Message Digest #5) is an older hash algorithm. It
is used with a 96 bit digest length for IPSec.
•
,$$
: All options can be used.
•
>,
(default value): SHA1 (Secure Hash Algorithm #1) is a
hash algorithm developed by NSA (United States National Se-
curity Association). It is rated as secure, but is slower than
MD5. It is used with a 96 bit digest length for IPSec.
•
>,
: SH2 (Secure Hash Algorithmus #2) is a hash al-
gorithm which has been designed to supersede SHA 1. It can
be used with hash lengths of 256, 384 or 512 bits.
•
>,
: SHA-2 with 384 bit hash length.
•
>,
: SHA-2 with 512 bit hash length.
Note that RipeMD 160 and Tiger 192 are not available for mes-
sage hashing in phase 2.
Depending on the hardware of your device some options may
not be available.
Use PFS Group
As PFS (Perfect Forward Secrecy) requires another Diffie-
Hellman key calculation to create new encryption material, you
must select the exponentiation features. If you enable PFS (
7+
), the options are the same as for the configuration of
DH Group in the VPN->IPSec->Phase-1 Profiles menu. PFS is
used to protect the keys of a renewed phase 2 SA, even if the
keys of the phase 1 SA have become known.
The following groups with their corresponding bit values are
available:
•
"( &#
•
" &#
•
" &#
•
" &#
•
"( &#
•
" &#
Depending on the hardware of your device some options may
not be available.
bintec elmeg GmbH
14 VPN
be.IP 4isdn
261