Configuring with Web Based Management
4.9 Security
SINEMA Remote Connect - Server
Operating Instructions, 11/2017, C79000-G8976-C383-04
103
6.
Specify the settings of phase 2 - IKE (KE/key exchange):
Box
Meaning
Protocol
Selection of the protocol
AH: The IP Authentication Header (AH) handles the authentication
and identification of the source.
ESP: The Encapsulation Security Payload (ESP) encrypts the data.
Encryption algorithm:
The selection depends on the phase und the key exchange method
(IKE)
Hash method
Selection of the authentication algorithm:
SHA 1, 256, 384, 512
Key derivation
Select the required Diffie-Hellmann group (DH) from which a key will
be generated.
Lifetime
The lifetime of the authentication. When the time has elapsed, the
VPN endpoints involved must authenticate themselves with each
other again and generate a new key
7.
Click "Finish".
Changing an IPsec profile
Change the corresponding user settings. Then click the "Save" button.
Encryption algorithm
Phase 1
Phase 2
IKEv1
IKEv2
IKEv1
IKEv2
3DES
x
x
x
x
AES128 CBC
x
x
x
x
AES192 CBC
x
x
x
x
AES256 CBC
x
x
x
x
AES128 CTR
-
x
x
x
AES192 CTR
-
x
x
x
AES256 CTR
-
x
x
x
AES128 CCM 16
-
x
x
x
AES192 CCM 16
-
x
x
x
AES256 CCM 16
-
x
x
x
AES128 GCM 16
-
x
x
x
AES192 GCM 16
-
x
x
x
AES256 GCM 16
-
x
x
x
x: is supported
-: is not supported