Field
Description
This option can only be configured if certificates are loaded.
13.1.3 Phase-2 Profiles
You can define profiles for phase 2 of the tunnel setup just as for phase 1.
In the VPN->IPSec->Phase-2 Profiles menu, a list of all configured IPSec phase 2 pro-
files is displayed.
In the Default column, you can mark the profile to be used as the default profile.
13.1.3.1 New
Choose the New button to create additional profiles.
The menu VPN->IPSec->Phase-2 Profiles->New consists of the following fields:
Fields in the Phase-2 (IPSEC) Parameters menu
Field
Description
Description
Enter a description that uniquely identifies the profile.
The maximum length of the entry is 255 characters.
Proposals
In this field, you can select any combination of encryption and
message hash algorithms for IKE phase 2 on your default. The
combination of six encryption algorithms and two message
hash algorithms gives 12 possible values in this field.
Encryption algorithms (Encryption):
•
C3
(default value): 3DES is an extension of the DES al-
gorithm with an effective key length of 112 bits, which is
rated as secure. It is the slowest algorithm currently suppor-
ted.
•
'' GG ''
: All options can be used.
•
3
: Rijndael has been nominated as AES due to its fast key
setup, low memory requirements, high level of security
against attacks and general speed. The partner's AES key
length is used here. If this has also selected the parameter
3
, a key length of 128 bits is used.
•
3' E
: Rijndael has been nominated as AES due to its
Gigaset Communications GmbH
13 VPN
hybird 120 Gigaset Edition
273