5-6 Firmware User Guide
that will be used to generate key material for IKE Phase 1.
■The Encryption Algorithm
■The Hash Algorithm
■The
■If you select Advanced IKE Phase 1 Options the Advanced IKE Phase 1 Options screen appears.
Advanced IKE Phase | 1 Options |
Negotiation... | Normal |
SA Use Policy... | Newest SAs Immediately |
Allow Dangling Phase 2 SAs: | Yes |
Phase 1 SA Lifetime (seconds): | 28800 |
Phase 1 SA Lifetime (Kbytes): | 0 |
Send Initial Contact Message: | Yes |
Include Vendor ID Payload: | Yes |
Independent Phase 2 | Yes |
Strict Port Policy: | No |
Return/Enter accepts * Tab toggles * ESC cancels.
Normally it is not necessary to change the settings of the items on the Advanced IKE Phase 1 Options screen. Most of these settings exist for ensuring compatibility with remote IKE implementations that may have certain limitations.
■The Negotiation
■The SA Use Policy
Because the router normally
■If you select Newest SAs Immediately, the router will begin using the newly created Phase 1 SAs immediately after they are negotiated.
■If you select Old SAs Until Expired, the router will continue using the old Phase 1 SAs until they expire and will begin using the newly created Phase 1 SAs only after the old ones are no longer valid.
■Allow Dangling Phase 2 SAs toggles whether or not Phase 2 SAs are permitted to survive the expiration of