Example

NGFW{running-phase1-proposal-myphase1}auth local pre-shared-key remote pre-shared-key

NGFW{running-phase1-proposal-myphase1}dh-group

ISAKMP Diffie-Hellman group.

Syntax

dh-group (12514)

Example

NGFW{running-phase1-proposal-myphase1}dh-group 5

NGFW{running-phase1-proposal-myphase1}encryption

ISAKMP encryption algorithm.

Syntax

encryption (3desaes128aes192aes256)

Example

NGFW{running-phase1-proposal-myphase1}encryption aes256

NGFW{running-phase1-proposal-myphase1}hash

ISAKMP hash algorithm.

Syntax

hash (md5sha1)

Example

NGFW{running-phase1-proposal-myphase1}hash sha1

NGFW{running-phase1-proposal-myphase1}lifetime

ISAKMP security association lifetime. 86400 seconds commonly used in phase 1 is 24 hours.

Syntax

lifetime LIFE-DURATION LIFE-UNIT lifetime (1-65535) (minsechour)

Example

NGFW{running-phase1-proposal-myphase1}lifetime 24 hour

running-phase1-proposal-X Context Commands and their Usage

NGFW{running}vpn ipsec

NGFW{running-ipsec}phase2 2 proposal myphase2

NGFW{running-phase2-proposal-myphase2}auth2

IPsec authentication algorithm.

NGFW Command Line Interface Reference 191

Page 199
Image 199
HP TippingPoint Next Generation Firewall manual Dh-group