
Robustel R3000 LG User Guide
RT_UG_R3000 LG_v.1.0.4 19 Jul., 2018 73/133
The window is displayed as below when choosing “xAuth CA” as the authentication type.
IKE Settings
Item
Description
Default
IKE Type
Select from “IKEv1” or “IKEv2” as IKE version.
IKEv1
Negotiation Mode
Select from “Main” and “Aggressive” for the IKE negotiation mode in phase 1.
If the IP address of one end of an IPsec tunnel is obtained dynamically, the IKE
negotiation mode must be aggressive. In this case, SAs can be established as
long as the username and password are correct.
Main
Authentication
Algorithm
Select from “MD5”, “SHA1”, “SHA2 256” or “SHA2 512” to be used in IKE
negotiation.
MD5
Encrypt Algorithm
Select from “3DES”, “AES128” and “AES256”to be used in IKE negotiation.
3DES: Use 168-bit 3DES encryption algorithm in CBC mode
AES128: Use 128-bit AES encryption algorithm in CBC mode
AES256: Use 256-bit AES encryption algorithm in CBC mode
3DES
IKE DH Group
Select from “DHgroup2”, “DHgroup5”, “DHgroup14”, “DHgroup15”,
“DHgroup16”, “DHgroup17” or “DHgroup18” to be used in key negotiation
phase 1.
DHgroup2
Authentication Type
Select from “PSK”, “CA”, “xAuth PSK” and “xAuth CA” to be used in IKE
negotiation.
PSK: Pre-shared Key
CA: x509 Certificate Authority
xAuth: Extended Authentication to AAA server
PSK
PSK Secret
Enter the pre-shared key.
Null
Local ID Type
Select from “Default”, “FQDN” and “User FQDN” for IKE negotiation.
Default: Use an IP address as the ID in IKE negotiation
FQDN: Use an FQDN type as the ID in IKE negotiation. If this option is
selected, type a name without any at sign (@) for the local security
gateway, e.g., test.robustel.com
User FQDN: Use a user FQDN type as the ID in IKE negotiation. If this
option is selected, type a name string with a sign “@” for the local
Default