G
ATEWAY
C
ONTROLLER
S
ERIES
U
SER
M
ANUAL
VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P
AGE
93
OF
135
Manual Phase 2
Protocol
The Controller uses the ESP protocol for VPN. Make sure
that this setting matches on the other VPN gateway.
Encryption
You can choose a faster DES encryption or slower 3DES.
3DES is more secure but require more resources.
Authentication
You can choose MD5 or SHA1. SHA1 is a little more secure.
Security Parameter Index
You must enter a hexadecimal value between 100
and FFF. This is used to identify the tunnel. The Controller
uses the same SPI for incoming and outgoing tunnels. This
value must match the setting on the other gateway.
Encryption Key
You must enter a hexadecimal value of the following
length:
DES: 16
3DES: 48
Authentication Key
You must enter a hexadecimal value of the following
length:
MD5: 32
SHA1: 40
Note: The other gateway m ay accept ASCII (2 byte) values for m anual keys and convert them
to hex, so m ake sure you account for this in matching the keys. Contact the vendor if you
are not able to determ ine the actual HEX key generated from the ASCII value, as they m ay
be hashing it or doing som e other transformation.
Monitoring VPN Tunnels
You can check the status of the VPN tunnels under System Status – VPN Tunnels.
Click on VPN Log to see a more detailed log of VPN activity.