V I R T U A L P R I V A T E N E T W O R K S
Configuring Internet Key Exchange
7-18
Security Appliance User Guide
Version 3R2
7
set ike gateway {name_str} ip {address_str} {main|
aggressive} outgoing-interface {name} preshare
{name_str} proposal {p1_name}
set vpn {name_str} gateway {gw_name} proposal {p2_name}
Table 7-5
shows the required Phase 1 and Phase 2 Proposal Settings.
Table 7-5: Required Phase 1 and Phase 2 IKE Proposal Settings
Tunnel Name
Name that uniquely identifies the VPN tunnel
IPSec Gateway
IP address or Fully Qualified Domain Name
Pre-Shared
Secret
Pass phrase used to authenticate VPN appliance.
IKE Identity
IPv4 address, e-mail address or FQDN
Phase 1
Exchange proposal to determine how to
authenticate and secure the channel.
Mode Exchange
Main or Aggressive
DH Group
1, 2 or 5
Protocol
AH, ESP
Encryption
DES, 3DES or AES
Authentication
MD5, SHA-1
SA Life Time
Lifetime for a single set of encryption keys.
Phase 2
Exchange that allows an SA to be created,
allowing for the secure transmission of data using
IPsec.
Encryption
DES, 3DES or AES
Authentication
MD5 or SHA-1
DH Group
1, 2 or 5
Protocol
AH or ESP
SA Life Time
Lifetime for a single set of encryption keys
Prefect Forward
Secrecy
Generates a new key for every message sent
through an SA.
Local Network
The local network attached to the VF-2112.
Destination
Network
Network to which the VPN tunnel will terminate
Содержание freeGuard Blaze 2100
Страница 1: ...freeGuard Blaze 2100 User Guide Version 3R2...
Страница 14: ...I NT R O DU C T I O N About Document Conventions 1 4 Security Appliance User Guide Version 3R2 1...
Страница 24: ...G E T T IN G S T A R T E D Installing the freeGuard Blaze 2100 2 10 Security Appliance User Guide Version 3R2 2...
Страница 82: ...SY ST EM MA N AGEM E N T Using Traceroute 4 22 Security Appliance User Guide Version 3R2 4...
Страница 192: ...P OL IC Y CO NF I G URA T IO N About Schedules 9 28 Security Appliance User Guide Version 3R2 9...
Страница 216: ...P R E DEF I N E D SER V IC ES A 4 Security Appliance User Guide Version 3R2 A...