SonicWALL VPN Page 113
Security policy Settings for IKE using Pre-shared Secret
•
Phase 1 DH Group
- Diffie-Hellman (DH) key exchange (a key agreement protocol) is
used during phase 1 of the authentication process to establish pre-shared keys. Select from
one of three settings:
- Group 1
-
Group 2
-
Group 5
Groups 1, 2, 5
use Modular-Exponential with different prime lengths as listed below:
If network speed is preferred, select
Group 1
. If network security is preferred, select
Group 5
. To compromise between network speed and network security, select
Group 2
.
•
SA Life time (secs) -
This field allows you to configure the length of time a VPN tunnel
is active. The default value is 28800 seconds (eight hours).
•
Phase 1 Encryption/Authentication
- You can also select an encryption method from
the
Encryption/Authentication
for the VPN tunnel. If you select
IKE using Pre-
Shared Secret
for your SA, you can select from one of four encryption methods:
-
DES & MD5
- DES & SHA1
- 3DES & MD5
- 3DES & SHA1
These are listed in order from least secure to most secure. If network speed is preferred,
then select
DES & MD5
. If network security is preferred, select
3DES & SHA1
. To
compromise between network speed and network security, select
DES & SHA1
.
•
Phase 2 Encryption/Authentication
- Each encryption method is described in the step
by step configuration instructions for
IKE using preshared secret
. However,
Phase 2
Encryption/Authentication
is different for the
Group VPN SA
. The VPN Client does not
support ArcFour encryption methods, and you cannot disable authentication in the VPN
Group
Descriptor
Prime
Size
(bits)
Group 1
768
Group 2
1024
Group 5
1536
Содержание TELE3 SP
Страница 1: ...SONICWALL The TELE3 SP Administrator s Guide...
Страница 204: ...Appendices Page 203 Notes...
Страница 205: ...Page 204 SonicWALL TELE3 SP Administrator s Guide...