IPL ROUTER SET-UP
Page 46
Setup Guide 9023409-01
Ethernet ADSL Cellular Routeur Firewall
IKE phase 2 Section
The purpose of IKE phase two is to negotiate the IPSec parameters (general parameters, encryption, SA life-
time…).
The result of the IKE phase 2 is the encrypted tunnel between the two routers.
«Protocol » parameter :
This parameter enables to set-up the IPSec transport protocol.
AH insures authentication only but does not encrypt the transported data.
ESP ensures routers authentication and data encryption.
ESP will be preferred.
«Data encryption algorithm » parameter :
Recommended value : AES
«Authentication algorithm» parameter :
SHA1 provides a better security than MD5.
«PFS» checkbox :
With PFS disabled, initial keying material is created during the key exchange in phase-1 of the IKE
negotiation. In phase-2 of the IKE negotiation, encryption and authentication session keys will be extracted
from this initial keying material. By using PFS, Perfect Forwarding Secrecy, completely new keying material
will always be created upon re-key. Should one key be compromised, no other key can be derived using that
information.
«DH group» parameter (only if the PFS option is enabled) :
Recommended value: Group 2.
«Life-time» parameter (only if the PFS option is enabled) :
Enter the phase 2 key life-time.
DPD section
DPD Keep-alive period” parameter : :
A DPD is a message sent periodically by each end-point to the other one to make sure that the VPN must be
left active.
This parameters sets the amount of time (in seconds) between two of these requests.
“Connection death time-out” parameter :
This parameter defines the maximum amount of time (in seconds) a VPN connection will stay established if
no traffic or no DPD keep-alive message are received from the remote point.