The VPN -> IPSec -> Phase-2 Profile-> New menu consists of the following fields:
Fields in the Phase-2 Profile Phase-2 (IPSEC) Parameters menu
Field
Description
Description
Enter a description that uniquely identifies the profile.
The maximum length of the entry is 255 characters.
Proposal
In this field, you can select any combination of encryption and
message hash algorithms for IKE phase 2 on your default. The
combination of six encryption algorithms and two message hash
algorithms gives 12 possible values in this field.
Encryption algorithms (Encryption):
•
3DES
(default value): 3DES is an extension of the DES al-
gorithm with an effective key length of 112 bits, which is rated
as secure. It is the slowest algorithm currently supported.
•
-ALL-
: All options can be used.
•
AES-128
: Rijndael has been nominated as AES due to its
fast key setup, low memory requirements, high level of secur-
ity against attacks and general speed. Here, it is used with a
key length of 128 bits.
•
AES-192
: Rijndael has been nominated as AES due to its
fast key setup, low memory requirements, high level of secur-
ity against attacks and general speed. Here, it is used with a
key length of 192 bits.
•
AES-256
: Rijndael has been nominated as AES due to its
fast key setup, low memory requirements, high level of secur-
ity against attacks and general speed. Here, it is used with a
key length of 256 bits.
•
Twofish
: Twofish was a final candidate for the AES
(Advanced Encryption Standard). It is rated as just as secure
as Rijndael (AES), but is slower.
•
Blowfish
: Blowfish is a very secure and fast algorithm.
Twofish can be regarded as the successor to Blowfish.
•
CAST
: CAST is also a very secure algorithm, marginally
slower than Blowfish, but faster than 3DES.
•
DES
: DES is an older encryption algorithm, which is rated as
weak due to its small effective length of 56 bits.
Funkwerk Enterprise Communications GmbH
11 VPN
bintec R200 Series
239