Set Up a Virtual Private Network (VPN)
103
l
In the Remote Side section, enter the LAN-side IP subnet of the gateway with the subnet
mask in CIDR format.
Note:
The gateway and the client’s network must have different subnet ranges that do not overlap.
8. Click the
Phase 1
tab.
9. Specify the following:
l
Lifetime: Enter
1800
and select
Seconds
.
l
DH Group: Select
1024 (2)
.
l
Encryption: Select
3DES
.
l
Authentication: Select
SHA-1
.
l
Exchange Mode: Select
Main
.
l
Proposal Check: Select
Obey
.
l
Nonce Size: Enter
16
.
10. Click the
Phase
2 tab.
11. Specify the following:
l
Lifetime: Enter
1800
and select
Seconds
.
l
PFS Group: Select
1024 (2)
.
l
Encryption: Select the
DES
,
3DES
,
AES 2256
,
AES 192
, and
AES 128
check boxes.
l
Authentication: Select the
HMAC MDS
and
HMAC SHA-1
check boxes.
12. Click the
ID
tab.
13. Specify the following:
l
Leave the Local Identifier and Remote Identifier fields set to
Address
.
l
Select
XAuth PSK
in the Authentication Method section and type the pre-shared key, user
name, and password that you specified in the gateway.
14. Click the
Options
tab.
15. Specify the following:
l
Select these check boxes:
o
IPSec DOI
o
SIT_IDENTITY_ONLY
o
Initial Contact
o
Enable MODE_CFG