Cisco Systems PIX515E quick start Configure the IKE Policy

Page 24

Step 3 Configure the IKE Policy

This step is comprised of two windows:

1.Configure the IKE negotiation parameters.

In most cases, the default values are sufficient to establish secure VPN tunnels between two peers.

a.Select the Encryption (DES/3DES/AES), Authentication algorithms (MD5/SHA), and the Diffie-Hellman group (1/2/5) used by the PIX 515E during an IKE security association. Confirm all values before moving to the next window.

Note When configuring PIX 2, enter the exact values for each of the options that you selected for PIX 1. Encryption mismatches are a common cause of VPN tunnel failures and can slow down the process.

b.Click the Next button to continue.

24

Image 24
Contents Cisco PIX 515E Firewall Hardware Features Software FeaturesAbout the Cisco PIX 515E Firewall 69-0123-01 69-0124-01 69-0125-01 Power cable Rubber feet Check Items IncludedInstall the PIX 515E DMZConfigure the PIX 515E Example Configurations DMZ ConfigurationManage IP Pools for Network Translations Select the Translation Rules tab Page Page Configure Address Translations on Private Networks Page Page Page Configure External Identity for the DMZ Web Server Configurations should display as shown below Provide Http Access to the DMZ Web Server Page Page Site-to-Site VPN Configuration Start the VPN Wizard Configure the VPN Peer Page Configure the IKE Policy Page Configure Internal Traffic Page View and Enable VPN Commands Optional Maintenance and Upgrade Procedures Establishing Site-to-Site VPNs with other Cisco ProductsObtaining DES and 3DES/AES Encryption Licenses Restore the Default Configuration Command DescriptionHttp 192.168.1.0 Alternative Ways to Access the PIX 515E Ethernet Check the LEDs LEDColor Status Description Obtaining Documentation Cisco.comDocumentation CD-ROM Ordering DocumentationDocumentation Feedback Obtaining Technical AssistanceCisco TAC Website Opening a TAC Case TAC Case Priority DefinitionsObtaining Additional Publications and Information Page USA