Configuring a SKIP VPN
Issue 4 May 2005 151
7. If you want to add User Objects or User Group Objects as members of this VPN Object, do
the following.
Click the Members-Users tab to bring it to the front.
From the Available list, select specific User Objects and User Group Objects. User
Group Objects are always located at the bottom of the list.
Note:
Note: Tip: Hold the Shift key to simultaneously select many adjacent items, or hold the
Crtl key to simultaneously select many non-adjacent items.
Click Move Left to move the selected items to the Current Members list.
8. If you want to add IP Group Objects as members of this VPN Object, do the following.
Click the Members-IP Groups tab to bring it to the front.
From the Available list, select specific IP Group Objects.
Click Move Left to move the selected items to the Current Members list.
9. Click the Security (SKIP) tab to bring it to the front.
10. From the Encryption Algorithm list, do one of the following.
Select Triple DES to divide VPN traffic into 64 bit blocks and encrypt each block three
times with three different keys.
Select DES to divide VPN traffic into 64 bit blocks and encrypt each block with a 56-bit
key.
Select NONE to not encrypt VPN traffic.
11. From the Authentication Algorithm drop-down list, do one of the following.
Select Keyed MD5 if you want VPN tunnel end-points to authenticate themselves using
the Message Digest 5 hash function.
Tunnel end-points are security gateways and VPNremote Clients.
Select NONE if you do not want tunnel end-point to authenticate themselves.
12. From the Compression Algorithm list, do one of the following.
Select Stac if you want the payloads of VPN packets to be compressed using the STAC
Lempel-Zif standard compression. Since encryption is time-consuming, compression
speeds up the entire process.
Select NONE you do not want payloads of VPN packets to be compressed.
13. Click Save to save your work.