To cancel the configuration and return to the main Configuration
page, click Cancel.
Table 63: IPsec Phase 2 Proposal
Options
Field
Function
Action
IPSec Proposal
(Phase 2)
Name
Description of the Phase 2 proposal.
Enter a name.
Description
Identify the proposal
Enter a text description.
Authentication algorithm
Hash algorithm that authenticates packet data. It can be one
of the following:
hmac-md5-96—Produces a 128-bit digest.
hmac-sha1-96—Produces a 160-bit digest.
Select a hash algorithm.
Encryption algorithm
Configures an IKE encryption algorithm.
3des-cbc—Has a block size of 24 bytes; the key size
is 192 bits long.
des-cbc—Has a block size of 8 bytes; the key size
is 48 bits long.
aes-128-cbc—AES 128-bit encryption algorithm.
aes-192-cbc—AES 192-bit encryption algorithm.
aes-256-cbc—AES 256-bit encryption algorithm.
Select an encryption algorithm.
Lifetime kilobytes
The lifetime (in kilobytes) of an IPsec security association
(SA). The SA is terminated when the specified number of kilobytes
of traffic have passed.
Enter a value from 64 through 1,048,576 bytes.
Lifetime seconds
The lifetime (in seconds) of an IKE security association (SA).
When the SA expires, it is replaced by a new SA and security parameter
index (SPI) or terminated.