8120-B1 User’s Guide
Select
Subnet
if there is a group of remote IP addresses access VPN tunnel or
Single Address if one remote IP address only.
Enter the remote
IP address for VPN
and its
Subnet mask.
Select the Key Exchange Method from
AUTO (IKE)
or
Manual.
Select
the
Authentication Method
from
Pre-Shared Key
or
Certification (X.509)
.
If the authentication method is Pre-Shared Key, enter the
Pre-Shared Key
. If the
authentication method is certificate (X.509), select the certificate from the list.
Select
to
Enable
or
Disable
the Perfect Forward Secrecy.
Click
the
Show Advanced Settings
to configure
Advanced IKE Settings.
Figure 58: Add a VPN IPSec Tunnel
Enter the Mode (Main or Aggressive), Encryption Algorithm (DES, 3DES,
AES128, AES196, AES256), Integrity Algorithm (MD5, SHA1), Select
Diffie-Hellman Group for Key Exchange, and Key Life Time for phase 1 to
establish an IPSec tunnel.
Enter the Encryption Algorithm (DES, 3DES, AES128, AES196, AES256),
Integrity Algorithm (MD5, SHA1), Select Diffie-Hellman Group for Key Exchange,
and Key Life Time for phase 2 to establish an IPSec tunnel.
Click
Save/Apply
to save the configuration.
45