Configure Advanced Features
68-4004214-01 Rev D
71
IPsec settings Section
With VPN tunnels there are two phases of Security Association (SA).
Phase 1 creates an Internet Key Exchange (IKE) SA
When Phase 1 is complete, Phase 2 creates one or more IPsec SAs that are then
used to key IPsec sessions
Field
Description
Pre-shared key
Allows you to enter the Pre-shared key of the firewall identifier if one
side of the VPN tunnel is using a unique firewall
Phase 1 DH group
Allows you to select one of following three Diffie-Hellman (DH)
encryption/decryption groups:
768 bits
1024 bits
1536 bits
Diffie-Hellman is a cryptographic technique that uses public and
private keys for encryption and decryption. The higher number of bits
selected, the more secure the connection
Phase 1 encryption
Allows you to select the form of encryption to secure the VPN
connection between endpoints. Select from the following five
encryption types:
DES
3DES
AES-128
AES-192
AES-256
You may choose any encryption type as long as the other end of the
VPN tunnel uses the same method
Phase 1 authentication Allows you to select an authentication type for another level of
security. Select one of the following authentication types:
MD5
SHA
You may choose either authentication type as long as the other end of
the VPN tunnel uses the same method
Note:
SHA is recommended because it is more secure.