| VPN Template Name |
|
| Negotiation mode |
Aggressive is faster, but
less secure. |
| IKE version |
IKE Version |
|
| Phase 1 proposal
(Authentication) |
| Identifier Type |
|
| Encryption algorithm |
Must match the setting
chosen on the remote side. |
| Hash algorithm |
Must match the setting
chosen on the remote side. |
| DH key group |
1 = 768 bit, 2 = 1024
bit, 5 = 1536 bit
Must match the setting chosen on the remote side. |
| Lifetime |
second, minute or hour |
| Authentication Method |
Must match the setting
chosen on the remote side. |
|
| Phase 2 proposal
(SA/Key Exchange) |
| Encryption algorithms |
Hint: use 3DES for best compatibility or if you have a hardware
crypto accelerator card. |
| Authentication algorithms |
Hint: MD5 is slightly faster than SHA1. |
| PFS key group |
1 = 768 bit, 2 = 1024
bit, 5 = 1536 bit |
| Lifetime |
second, minute or hour |