‣
VPN Policy Name: Enter a name for the VPN Policy ➑.
You can use the same name you used for the IKE policy.
‣
IKE Policy: Select the IKE Policy you have just created
‣
Remote VPN Endpoint: Select “Fully Qualified Domain
Name”, and enter the same identifier here that you used
as the Remote Identity ➌ in the IKE policy
‣
SA Life Time: 3600 seconds / 0 Kbytes
‣
IPsec PFS: Keep IPsec PFS turned off
‣
PFS Key Group: Keep the selected “Group 1 (768 Bit)”
Advanced Users You can turn on Perfect Forward Secrecy (PFS) later, if you wish. The setting on the device must
match the setting in VPN Tracker (Advanced > Phase 2 > Perfect Forward Secrecy).