
User Interface
R&S
®
GP-U/GP-E/GP-S/GP-T
110
User Manual 3646.3836.02 ─ 01
Field
Description
"IKE Version"
Select the Internet key exchange version to be used for the connection. IKEv2
is faster in establishing a tunnel and in rekeying. IKEv1 is maintained for com-
patibility reasons.
Note:
If you select the gateprotect VPN client as connection type or if you
enable L2TP in a Client-to-Site connection, IKEv2 is not available.
"Encryption algorithm"
Select the cryptographic hash to verify the message.
"Authentication algo-
rithm"
Select the algorithm to encrypt the message.
"DH group"
Select the Diffie-Hellman (DH) group to be used for IKE negotiation.
"Lifetime"
Specify the timeout (in seconds) after which the IKE connection expires and a
new exchange is performed.
Note:
This only has an indirect influence on the renegotiation time. The precise
point in time is determined randomly to avoid that all tunnels are re-established
at the same time which would result in a heavy system load.
"Use mobile IKE"
Only with IKEv2: Select this checkbox to allow one side to change its IP
address without disconnecting the tunnel.
On the "IPsec" tab, you can select the encryption and authentication algorithms for the
IPsec SA negotiation quick mode:
Field
Description
"Encryption algorithm"
Select the cryptographic hash to verify the message.
"Authentication algo-
rithm"
Select the algorithm to encrypt the message.
"Lifetime"
Specify the timeout (in seconds) after which the IPsec SA expires and a new
exchange is performed.
Note:
This only has an indirect influence on the renegotiation time – the precise
point in time is determined randomly to avoid that all tunnels are re-established
at the same time which would result in a heavy system load.
"Perfect Forward
Secrecy (PFS)"
Select this checkbox to activate Perfect Forward Secrecy.
Using PFS is recommended because it increases security. However, it has to
be deactivated if the remote end does not support it (such as Windows XP).
Note:
If you select IKEv2, PFS is automatically used.
"PFS group"
Only if PFS is enabled: Select the Diffie-Hellman (DH group) to be used with
PFS.
On the "Additional Settings" tab, you can set up port and protocol restrictions (for
example for L2TP) for the IPsec connection. Only packets matching the settings are
forwarded through the tunnel.
Field
Description
"Local Port"
Enter the local port you want to restrict traffic to.
"Remote Port"
Enter the remote port you want to restrict traffic to.
Menu Reference