DEFINING TUNNELS
66 MultiConnect
®
rCell 100 MTR-EV3 User Guide
Field Description
Encryption Method Choose an Encryption Method from the following list: 3DES, AES-128,
AES-192, AES-256, or ADVANCED. IKE encryption algorithm is used for
the connection (phase 1 - ISAKMP SA). Based off of phase 1, a secure set
of defaults are used for phase 2, unless the Advanced option is used, in
which case, all components of both phases 1 and 2 are specified by the
user.
Phase 1 Encryption If Advanced is selected for Encryption Method, select Phase 1
Encryption from the drop-drown: 3DES, AES-128, AES-192, AES-256,
ANY AES, or ANY.
Phase 1 Authentication If Advanced is selected for Encryption Method, select Phase 1
Authentication from the drop-drown: MD5, SHA-1, SHA-2, SHA2-256,
SHA2-384, SHA2-512, or ANY.
Phase 1 Key Group If Advanced is selected for Encryption Method, select the Phase 1 Key
Group from the drop-down: DH2 (1024-bit), DH5 (1536-bit), D14 (2048-
bit), DH15 (3072-bit), DH16 (4096-bit), DH17 (6144-bit), DH18 (8192-
bit), DH22 (1024-bit), DH23 (2048-bit), DH24 (2048-bit), and ANY.
Phase 2 Encryption If Advanced is selected for Encryption Method, select Phase 2
Encryption from the drop-drown: 3DES, AES-128, AES-192, AES-256,
ANY AES, or ANY.
Phase 2 Authentication If Advanced is selected for Encryption Method, select Phase 2
Authentication from the drop-drown: MD5, SHA-1, SHA-2, SHA2-256,
SHA2-384, SHA2-512, or ANY.
Phase 2 Key Group If Advanced is selected for Encryption Method, select the Phase 2 Key
Group from the drop-down: DH2 (1024-bit), DH5 (1536-bit), D14 (2048-
bit), DH15 (3072-bit), DH16 (4096-bit), DH17 (6144-bit), DH18 (8192-
bit), DH22 (1024-bit), DH23 (2048-bit), DH24 (2048-bit), and ANY.
Enable UID Unique Identifier String to enable the Local ID and Remote ID fields.
Local ID String Identifier for the local security gateway (optional)
Remote ID String Identifier for the remote security gateway (optional)
IPSec Tunnel: Advanced
IKE Lifetime Duration for which the ISAKMP SA exists from successful negotiation to
expiration.
Key Life Duration for which the IPsec SA exists from successful negotiation to
expiration.
Max Retries Number of retry attempts for establishing the IPsec tunnel. Enter zero
for unlimited retries.
Compression Enable IPComp. This protocol increases the overall communication
performance by compressing the datagrams. Compression requires
greater CPU processing.