Next select the ‘Network’ tab.

In the ‘Local Networks’ section, select the radio button next to ‘Choose local network from list’ and select "LAN Primary Subnet" from the dropdown box.

In the ‘Destination Networks’ section, select the radio button next to ‘Choose destination network from list’ and select "checkpoint_group" from the dropdown box.

Next select the ‘Proposals’ tab. The default values should be correct, except the ‘Life Time’; normally "28800" should be lowered to "3600" in both Phase 1 and 2 proposals. Verify that all values are correct.

IKE (Phase 1) Proposal

Exchange: Aggressive Mode

DH Group: Group 5

Encryption: 3DES

Authentication: SHA1

Life Time (seconds): 3600

10

Page 10
Image 10
SonicWALL TZ170 manual IKE Phase 1 Proposal