In this field...
Do this...
P
erfect Forward
Specify whether to enable Perfect Forward Secrecy (PFS), by selecting
Secrec
y
one of the following:
•
•
Enabling PFS will g
and renew th
PFS increases security but lowers performance. It is recommended to
enable PFS only in situations where extreme security is required.
D
iffie-Hellman
Select the Diffie-H
gr
oup
•
•
A group with more bits ensures a stronger key but lowers performance.
Rene
gotiate every
Type the interval in seconds betwee
the IKE Phase-2 SA lifetime.
A shorter interval ensures higher security.
The defau
Chapter 12: Working With VPNs
Enabled. PFS is ena
bled. The Diffie-Hellman group field is
enabled.
Disabled. PFS is disabled. This is the default.
enerate a new Diffie-Hellman key during IKE Phase 2
e key for each key exchange.
ellman group to use:
Automatic. The NetDefend firewall automatically selects a
group. This is the default.
A specific group
lt value is 3600 seconds (one hour).
Adding and Editing VPN Sites
n IPSec SA key negotiations. This is
339