Manual

Table Of Contents
Software User Guide 81
Network Tab
Phase1DHGroup:SelecttheDHGroupneededforphase1(IKE)bychoosingoneofthevaluesfromthedropdown
listprovided.ThisoptionselectstheencryptionleveloftheDiffieHellmankeysandtheseareGroup1(768bits),
Group2(1024bits),Group5(1536bits)
orGr oup14(2048bits).Longerkeysimplybettersecuritybutatacostoflon
gernegotiation/setuptimeduringtheinitialconnectionestablishment.Thesesettingsmustmatchonbothendsof
theconnection.AvalueofNone
meansthatnoDHGroupwill beselectedforthisendofthetunnelanditwilladopt
thesettingsofitspeerduringconnectioninitiation.
Phase1ISAKMPTime(minutes):Selecthowlong,inminutes,thekeyingchannelofaconnection(ISAKMPSA)should
lastbeforebeingrenegotiated.
PreShared
Key(Required):Specifythekeytobeexchangedforencryptionnegotiationduringphase(IKE).Keymust
notcontainadoublequotecharacter.Note:ThePreSharedKeymustmatchonbothendsofthetunnelinorderto
work.
LocalPeerID:Specif y howtheleftparticipantshouldbeidentifiedfor
authentication.CanbeanIPaddressofafully
qualifieddomainnameprecededby@(whichisusedasaliteralstringandnotresolved).
RemotePeerID:Specif yhowtherightparticipantshouldbeidentifiedforauth entication.CanbeanIPaddressofa
fullyqualifieddomainnameprecededby
@(whichisusedasaliteralstringandnotresolved).
Phase2AuthType:DefineswhetherauthenticationshouldbedoneaspartofESPencryption,orseparatelyusingthe
AHprotocol.
Phase2Encryption:SelecttheESPencryptionalgorithmtobeusedfortheconnection.
Phase2Authentication:SelecttheESP
authenticationalgorithmtobeusedfortheconnection.
Phase2ISAKMPTime(minutes):Selecthowlong, inminutes,aparticularinstanceofaconnection(asetofencryp
tion/authenticationkeysforuserpackets)shouldlast,fromsuccessfulnegotiationtoexpiration.
ClickontheNEXTbuttonandthefollowingTerminationSettingsdialog
windowwillappear:
LocalPublicIPAddress:ThisparametertypicallyonlyneedstobespecifiedwhentheRedLionrouterisconfiguredto
usemorethanoneexternal,untrustedinterface.SpecifytheIPAddressoftheleftparticipant’spublicnetworkinter
face.