Digi IX40 User Manual page 375

Table of Contents

Advertisement

Virtual Private Networks (VPN)
The default is 3des.
iii. Set the type of hash to use during phase 1 to verify communication integrity:
(config vpn ipsec tunnel ipsec_example ike phase1_proposal 0)> hash value
(config vpn ipsec tunnel ipsec_example ike phase1_proposal 0)>
where value is one of:
The default is sha1.
iv. Set the type of Diffie-Hellman group to use for key exchange during phase 1:
i. Use the ?to determine available Diffie-Hellman group types:
ii. Set the Diffie-Hellman group type:
The default is modp2048.
v. (Optional) Add additional phase 1 proposals:
i. Move back one level in the schema:
ii. Add an additional proposal:
IX40 User Guide
n
aes192gcm128
n
aes192gcm64
n
aes192gcm96
n
aes256
n
aes256gcm128
n
aes256gcm64
n
aes256gcm96
n
null
n
md5
n
sha1
n
sha256
n
sha384
n
sha512
(config vpn ipsec tunnel ipsec_example ike phase1_proposal 0)> dh_group ?
curve25519
curve448
ecp192
ecp224
...
(config vpn ipsec tunnel ipsec_example ike phase1_proposal 0)>
(config vpn ipsec tunnel ipsec_example ike phase1_proposal 0)> dh_group value
(config vpn ipsec tunnel ipsec_example ike phase1_proposal 0)>
(config vpn ipsec tunnel ipsec_example ike phase1_proposal 0)> ..
(config vpn ipsec tunnel ipsec_example ike phase1_proposal)>
IPsec
375

Advertisement

Table of Contents
loading

Table of Contents