-
For Key Exchange Method, select Auto (with IKEv1).
-
From the IKEv1 Policy list, select remoteVPN.
-
Select the Enable PFS (Perfect Forward Secrecy) for keys check box, which forces the tunnel endpoints to periodically generate new keys for the IPsec SA.
-
From the Diffie-Hellman (DH) Group list, select Group 2 (1024).
-
For SA Lifetime in seconds, type 28800.
-
For SA lifetime in kilobytes, type 0.
-
Click Next.
|
-
Click Security Policy again.
-
Select the Enable Perfect Forward Secrecy (PFS) check box.
-
For PFS Key Group, select Diffie-Hellman Group 2.
-
Under Key Exchange (Phase 2), click Proposal 1.
-
For SA Life, select Seconds.
-
Type 28800 in the Seconds box.
|