V I R T U A L P R I V A T E N E T W O R K S
Configuring Internet Key Exchange
7-22
Security Appliance User Guide
Version 3R2
7
3
Objects > Address Objects > Add Object: Enter the following, then click
Apply
:
Name: sf_destination
IP Address/Netmask: 10.0.0.0/24
Zone: Untrust
VPN
1
VPN > Phase 1 Proposal Edit
2
Enter the following, then click
Apply
:
Name: encryptaesp1
Authentication Method: PSK
DH Group: Group-5
Encryption Algorithm: aes-128
Hash Algorithm: SHA-1
3
VPN > Phase 2 Proposal Edit
4
Enter the following, then click
Apply
:
Name: encryptaesp2
PSF: PSF-Group5
Encryption Algorithm: aes-128
Hash Algorithm: SHA-1
Seconds: 28800
5
VPN > IKE Gateway Edit
6
Enter the following, then click
Apply
:
Gateway name: to_sanfrancisco
Remote IPsec Gateway IP: 4.4.4.1
Outgoing interface: eth1
Phase 1 Proposal: encryptaesp1
Routing
1
Network > Route Add