Setting Authentication Only Authentication and Low
Level Encryption
Authentication and High
Level Encryption
Phase 1 Diffie-
Hellman Group
2 2 2
Phase 2 Security
Protocol
AH ESP ESP
Phase 2
Authentication
Algorithm
HMAC-SHA1-96/
HMAC-
SHA256-128/
HMAC-
SHA384-192/
HMAC-
SHA512-256
HMAC-SHA1-96/
HMAC-
SHA256-128/
HMAC-
SHA384-192/
HMAC-SHA512-256
HMAC-SHA256-128/
HMAC-SHA384-192/
HMAC-SHA512-256
Phase 2 Encryption
Algorithm
Permissions
Cleartext (NULL
encryption)
3DES/AES-128/
AES-192/AES-256
AES-128/AES-192/
AES-256
Phase 2 PFS Inactive Inactive 2
Encryption key auto exchange settings items
When you specify a security level, the corresponding security settings are automatically
configured, but other settings, such as address type, local address, and remote address must still be
configured manually.
After you specify a security level, you can still make changes to the auto configured settings. When
you change an auto configured setting, the security level switches automatically to "User Setting".
Setting Description Setting value
Address Type Specify the address type for
which IPsec transmission is
used.
• Inactive
• IPv4
• IPv6
• IPv4/IPv6 (Default
Settings only)
Configuring IPsec Settings
95