ZyWALL 5/35/70 Series User's Guide
Table 19 VPN Wizard: IPSec Setting (continued)
LABEL
Perfect Forward
Secret (PFS)
Back
Next
3.7 VPN Wizard Status Summary
This read-only screen shows the status of the current VPN setting. Use the summary table to
check whether what you have configured is correct.
106
DESCRIPTION
Perfect Forward Secret (PFS) is disabled (None) by default in phase 2 IPSec
SA setup. This allows faster IPSec setup, but is not so secure.
Select DH1 or DH2 to enable PFS. DH1 refers to Diffie-Hellman Group 1 a 768
bit random number. DH2 refers to Diffie-Hellman Group 2 a 1024 bit (1Kb)
random number (more secure, yet slower).
Click Back to return to the previous screen.
Click Next to continue.
Chapter 3 Wizard Setup