Parameter
User name
User password
Group name
Group password
IKE Proposal
This section can be used to configure the phase 1 settings:
Parameter
Negotiation mode
Encryption algorithm
Authentication
algo-
rithm
IKE
Diffie-Hellman
Group
SA life time
Perfect Forward Secrecy Specifies whether Perfect Forward Secrecy (PFS) should be
IPsec Proposal
This section can be used to configure the phase 2 settings:
Parameter
Encapsulation mode
IPsec protocol
Encryption algorithm
NB3700 User Manual 3.8
IPsec XAUTH Settings
The name of the XAUTH user
The password of the XAUTH user
The group ID
The group secret
IPsec IKE Proposal Settings
Choose the desired negotiation mode.
mode should be used but aggressive mode might be ap-
plicable when dealing with dynamic endpoint addresses.
The desired IKE encryption method (we recommend
AES256)
The desired IKE authentication method (we prefer SHA1
over MD5)
The IKE Diffie-Hellman Group
The lifetime of Security Associations
used. This feature increases security as PFS avoids pene-
tration of the key-exchange protocol and prevents compro-
misation of previous keys.
IPsec Proposal Settings
The desired encapsulation mode (Tunnel or Transport)
The desired IPsec protocol (AH or ESP)
The desired IKE encryption method (we recommend
AES256)
89
Preferably, main
Need help?
Do you have a question about the NB3700 and is the answer not in the manual?
Questions and answers