ThisdefinesthepeerauthenticationpresharedkeyusedtoauthenticatethisVPN
connection.Theconnectionwillbeuponlyifthepresharedkeysoneachsidematch.
Remote
Certificate
(pem
encoded)
AvailableonlywhenX.509CertificateischosenastheAuthenticationmethod,thisfield
allowsyoutopasteavalidX.509certificate.
InMainMode,thisfieldcanbeleftblank.InAggressiveMode,ifRemoteGatewayIP
Addressisfilledonthisendandthepeerend,thisfieldcanbeleftblank.Otherwise,this
fieldistypicallyaUFQDN.
InMainMode,thisfieldcanbeleftblank.InAggressiveMode,ifRemoteGatewayIP
Addressisfilledonthisendandthepeerend,thisfieldcanbeleftblank.Otherwise,this
fieldistypicallyaUFQDN.
InMainMode,thisallowssettinguptosixencryptionstandards,indescendingorderof
priority,tobeusedininitialconnectionkeynegotiations.InAggressiveMode,onlyone
selectionispermitted.
ThisistheDiffieHellmangroupusedwithinIKE.Thisallowstwopartiestoestablisha
sharedsecretoveraninsecurecommunicationschannel.Thelargerthegroupnumber,
thehigherthesecurity.
Group2:1024bitisthedefaultvalue.
Group5:1536bitisthealternativeoption.
ThissettingspecifiesthelifetimelimitofthisPhase1SecurityAssociation.Bydefault,itis
setat3600seconds.
InMainMode,thisallowssettinguptosixencryptionstandards,indescendingorderof
priority,tobeusedfortheIPdatathatisbeingtransferred.InAggressiveMode,only
oneselectionispermitted.
Perfectforwardsecrecy(PFS)ensuresthatifakeywascompromised,theattackerwill
beabletoaccessonlythedataprotectedbythatkey.
NoneDonotrequestforPFSwheninitiatingconnection.However,sincethereisno
validreasontorefusePFS,thesystemwillallowtheconnectiontousePFSifrequested
bytheremotepeer.Thisisthedefaultvalue.
Group2:1024bitDiffieHellmangroup.Thelargerthegroupnumber,thehigherthe
security.
Group5:1536bitisthethirdoption.
ThissettingspecifiesthelifetimelimitofthisPhase2SecurityAssociation.Bydefault,itis
setat28800seconds.
IPsecStatusshowsthecurrentconnectionstatusofeachconnectionprofileandisdisplayedat
Status>IPsecVPN.
Copyright@2019Peplink