
Chapter 7 VPN
206 X Family LSM User’s Guide V 2.5.1
Configure Phase 1 Setup Parameters for an IKE Proposal
The values specified for Phase 1 IKE negotiation must match the values configured on the remote
device.
STEP 1
From the LSM menu, select VPN > IKE Proposals.The VPN - IKE Proposals page displays.
STEP 2
On the IKE Proposals page, click Create, or to edit an existing IKE proposal, click its Pencil
icon.
STEP 3
If you are creating a new proposal, type the Proposal Name.
You cannot change the name of an existing proposal.
STEP 4
Select the required encryption and integrity combinations from the Encryption and Integ-
rity drop-down lists.
For information on these fields, refer to “IKE Proposal Configuration Parameters: Phase 1
and 2” on page 202.
STEP 5
Select the Diffie-Hellman Group from the drop-down list.
STEP 6
In the Lifetime field, enter the length of time you want the security association to last before
new authentication and encryption keys must be exchanged (between 1 and 65535 seconds,
default 28800).
A lower value increases security, but may be inconvenient, since the connection is temporary
disabled.
STEP 7
From the Authentication Type drop-down list, select the method to use for authenticating
access to the VPN:
• Pre-Shared Key — default level of security
• X.509 Certificates — highest level of security
STEP 8
Optionally, check Enable Aggressive Mode if the external IP address is not fixed. This set-
ting is not recommended.
Phase 2 Local
ID
configuration
options
These options determine how the device negotiates IKE Phase 2 local-id
checking:
• Select Enable strict ID checking of local network to restrict the use of the
Phase 2 tunnel to packets with a source IP address corresponding to a local-id
configured for the local network of the IPSec security association. For
backwards compatibility with the 2.2 release, this field is disabled by default.
• Select Use ID of 0.0.0.0/0 for local and remote networks to create a single
phase 2 SA for all traffic using local ID of 0.0.0.0/0 and remote ID of 0.0.0.0/0.
This option allows interoperability with devices from other vendors such as
Netscreen which always negotiate Phase 2 IDs as 0.0.0.0/0.
Table 7–5: IKE Proposal Phase 1 and Phase 2 Configuration Parameters (Continued)
Parameter Description
Kommentare zu diesen Handbüchern