ZyWALL 2 Series User’s Guide
Table
FIELD | DESCRIPTION | EXAMPLE |
|
|
|
Encapsulation | Press [SPACE BAR] to choose from Tunnel mode or Transport mode and | Tunnel |
| then press [ENTER]. See earlier for a discussion of these. |
|
|
|
|
Perfect | Perfect Forward Secrecy (PFS) is disabled (None) by default in phase 2 | None |
Forward | IPSec SA setup. This allows faster IPSec setup, but is not so secure. Press |
|
Secrecy (PFS) | [SPACE BAR] and choose from DH1 or DH2 to enable PFS. DH1 refers to |
|
|
| |
| Group 2 a 1024 bit (1Kb) random number (more secure, yet slower). |
|
|
|
|
When you have completed this menu, press [ENTER] at the prompt “Press ENTER to Confirm…” to save your configuration, or press [ESC] at any time to cancel.
37.5 Manual Setup
You only configure Menu 27.1.1.2 – Manual Setup when you select Manual in the Key Management field in Menu 27.1.1 – IPSec Setup. Manual key management is useful if you have problems with IKE key management.
37.5.1 Active Protocol
This field is a combination of mode and security protocols used for the VPN. See the Web Configurator User’s Guide for more information on these parameters.
TableMODE | SECURITY PROTOCOL |
|
|
Tunnel | ESP |
|
|
Transport | AH |
|
|
37.5.2 Security Parameter Index (SPI)
VPN/IPSec Setup |