VPN tunnel between SCALANCE M-800 and S612
3.2 Secure VPN tunnel with PSK
SCALANCE M-800 Getting Started
102 Getting Started, 06/2015, C79000-G8976-C337-04
Pre Shared Key: 12345678 Security > IPSec VPN > Authentication > PSK und PSK Confirma-
Remote ID: U28098881@GEA32 Security > IPSec VPN > Authentication > Remote ID
not required. The external IP address of the S612 is entered in the
WBM. In this example, this is 192.168.184.2
Local ID: U269159D5@GEA32 Security > IPSec VPN > Authentication > Local ID
not required. The entry remains empty in the WBM.
Remote net address: 192.168.184.0
Security > IPSec VPN > Remote End > Remote Subnet:
192.168.184.0/24
Remote subnet mask: 255.255.255.0
Local net address: 192.168.100.0
Security > IPSec VPN > Connections > Local Subnet:
192.168.100.0/24
Local subnet mask: 255.255.255.0
IPsec VPN > Connections > Edit IKE
Security > IPSec VPN > Connections > Keying Protocol: IKEv1
ISAKMP-SA encryption: 3DES-168
Security > IPSec VPN > Phase 1 > Encryption: 3DES
Security > IPSec VPN > Phase 1 > Authentication: SHA-1
ISAKMP-SA mode: Main mode
ISAKMP-SA lifetime (seconds): 86400
The value is specified in seconds in the text file. In
the WBM, the value must be entered in minutes.
Security > IPSec VPN > Phase 1 > Liftime [min]: 1440
IPsec SA encryption: 3DES-168
Security > IPSec VPN > Phase 2 > Encryption: 3DES
Security > IPSec VPN > Phase 2 > Authentication: SHA-1
IPsec SA lifetime (seconds): 86400
The value is specified in seconds in the text file. In
the WBM, the value must be entered in minutes.
Security > IPSec VPN > Phase 2 > Liftime [min]: 1440
Perfect Forward Secrecy (PFS): Nein
DH/PFS group: DH-2 1024 Security > IPSec VPN > Phase 1 > Key Derivation: DH group 2
Security > IPSec VPN > Phase 2 > Key Derivation: DH group 2
DPD timeout (seconds): 60
Security > IPSec VPN > Phase 1 > DPD-Timeout [sec]: 60