ZyWALL 5/35/70 Series User’s Guide
Table 18 VPN Wizard: IPSec Setting (continued)
LABEL | DESCRIPTION |
|
|
SA Life Time | Define the length of time before an IKE SA automatically renegotiates in this |
(Seconds) | field. The minimum value is 180 seconds. |
| A short SA Life Time increases security by forcing the two VPN gateways to |
| update the encryption and authentication keys. However, every time the VPN |
| tunnel renegotiates, all users accessing remote resources are temporarily |
| disconnected. |
Perfect Forward | Perfect Forward Secret (PFS) is disabled (None) by default in phase 2 IPSec |
Secret (PFS) | SA setup. This allows faster IPSec setup, but is not so secure. |
| Select DH1 or DH2 to enable PFS. DH1 refers to |
| bit random number. DH2 refers to |
| random number (more secure, yet slower). |
Back | Click Back to return to the previous screen. |
|
|
Next | Click Next to continue. |
|
|
3.7 VPN Wizard Status Summary
This
99 | Chapter 3 Wizard Setup |