Configuring Virtual Private Networks (VPNs) and Security
Configuring Advanced VPN Parameters
Cisco RV120W Administration Guide
95
5
Configuring IKE Policies
The Internet Key Exchange (IKE) protocol dynamically exchanges keys between
two IPsec hosts. You can create IKE policies to define the security parameters
such as authentication of the peer, encryption algorithms, etc. to be used in this
process. Be sure to use compatible encryption, authentication, and key-group
parameters for the VPN policy.
To configure IKE Policies:
STEP 1
Choose VPN > IPsec > Advanced VPN Setup. In the IKE Policy table, click Add.
STEP 2
Under Policy Name, enter a unique name for the policy for identification and
management purposes.
STEP 3
Under Direction/Type, choose one of the following connection methods:
•
Initiator—The router will initiate the connection to the remote end.
•
Responder—The router will wait passively and respond to remote IKE
requests.
•
Both—The router will work in either Initiator or Responder mode.
STEP 4
Under Exchange Mode, choose one of the following options:
•
Main—This mode negotiates the tunnel with higher security, but is slower.
•
Aggressive—This mode establishes a faster connection, but with lowered
security.
NOTE
If either the Local or Remote identifier type is not an IP address, then
negotiation is only possible in Aggressive Mode. If FQDN, User FQDN or DER
ASN1 DN is selected, the router disables Main mode and sets the default to
Aggressive mode.
STEP 5
In the Local section, under Identifier Type, choose the Internet Security
Association and Key Management Protocol (ISAKMP) identifier for this router:
•
Local WAN (Internet) IP
•
FQDN
•
User-FQDN
•
DER ASN1 DN