Select Diffie-Hellman Group
for Key Exchange
Key Life Time
Phase 2
Encryption Algorithm
Integrity Algorithm
Select Diffie-Hellman Group
for Key Exchange
Key Life Time
Define the group used for the Diffie-Hellman
exponentiations. This directive must be defined.
group is one of following: modp768, modp1024,
modp1536, modp2048, modp3072, modp4096,
modp6144, modp8192.
When you want to use aggressive mode, you must
define the same DH group in each proposal.
Define lifetime of the phase 1 SA proposal.
Specify the encryption algorithm used for the phase 2
negotiation. This directive must be defined.
Algorithm is one of following: des,
3des, aes-128(192, 256) for Oakley
Define the hash algorithm used for the phase 2.
Algorithm is one of following: md5, sha1 for Oakley
Define the group of Diffie-Hellman exponentiations.
If you do not require PFS then you can omit this
directive.
Any proposal will be accepted if you do not specify
one.
Define how long an IPsec-SA will be used, in time
units. Any proposal will be accepted, and no
attribute(s) will be proposed to the peer if you do not
specify it(them).
84