![Niveo NR-70 Скачать руководство пользователя страница 160](http://html1.mh-extra.com/html/niveo/nr-70/nr-70_user-manual_1696836160.webp)
}
Figure 10-16 IPSec Advanced settings
Exchange Mode:
Specify the exchange mode used for IKE phase 1 negotiation.
The available options are
Main
and
Aggressive
. If the
Connection Type
is
Bidirectional
, you should choose
Main
mode; else, you should choose
Aggressive
mode.
SA Lifetime:
It refers to IKE SA lifetime, which specifies the number of seconds
(at least 600 seconds) an IKE SA will exist before expiring. A new IKE SA is
negotiated 540 seconds before the existing IKE SA expires.
Encrypt/Auth Algorithms 1 ~ Encrypt/Auth Algorithms 4 (Phase 1):
They
refer to phase 1 proposal that specifies a set of security algorithms for phase 1
negotiation. A phase 1 proposal includes an encryption algorithm, an
authentication algorithm, and a DH group. You can choose up to four phase 1
proposals.
Encrypt/Auth Algorithms 2 ~ Encrypt/Auth Algorithms 4 (Phase 2):
They
refer to phase 2 proposal that specifies a set of security protocols and algorithms
for phase 2 negotiation. You can choose up to three phase 2 proposals together
with
P2 Encrypt/Auth Algorithms 1
.
SA Lifetime:
It refers to IPSec SA time lifetime, which specifies the number of
seconds (at least 600 seconds) an IPSec SA will exist before expiring. A new
IPSec SA is negotiated 540 seconds before the existing IPSec SA expires.