User`s manual
Select Diffie-Hellman Group
for Key Exchange
Define the group used for the Diffie-Hellman
exponentiations. This directive must be defined.
group is one of following: modp768, modp1024,
modp1536, modp2048, modp3072, modp4096,
modp6144, modp8192.
When you want to use aggressive mode, you must
define the same DH group in each proposal.
Key Life Time Define lifetime of the phase 1 SA proposal.
Phase 2
Encryption Algorithm Specify the encryption algorithm used for the phase 2
negotiation. This directive must be defined.
Algorithm is one of following: des,
3des, aes-128(192, 256) for Oakley
Integrity Algorithm Define the hash algorithm used for the phase 2.
Algorithm is one of following: md5, sha1 for Oakley
Select Diffie-Hellman Group
for Key Exchange
Define the group of Diffie-Hellman exponentiations.
If you do not require PFS then you can omit this
directive.
Any proposal will be accepted if you do not specify
one.
Key Life Time Define how long an IPsec-SA will be used, in time
units. Any proposal will be accepted, and no
attribute(s) will be proposed to the peer if you do not
specify it(them).
84