100 | Chapter 6 - VPN Ports and |
|
|
•If Respond is selected, this Tunnel Partner will use IKE, but will only respond to tunnel establishment attempts which have been initiated by other devices. It will not initiate tunnel establishment.
Shared Key
This is a shared alphanumeric secret between
Transform
This list box specifies the protection types and algorithms which will be used for tunnel sessions. Each option is a protection piece which specifies the authentication and/or encryption parameters to be used.
Use the Move Up and Move Down buttons to arrange the priority of the protection options.
>Perfect Forward Secrecy
Perfect Forward Secrecy (PFS) allows you to add an additional security parameter to tunnel sessions. PFS means that every time encryption and/or authentication key are computed, a new
•If No PFS is selected, this security parameter will not be added for this group configuration.
•If Phase 1 Group is selected, the group used in Phase 1 of the IKE nego- tiation is used as the group for the PFS
•If DH Group 1 is selected, the
•If DH Group 2 is selected, the