System > Network > VPN > IPSec VPN
P1 proposal is the IKE security proposal that can be applied to the ISAKMP gateway, and is used in the Phase 1 SA.
In the P1 Proposal tab of the IPSec VPN page, you can perform the following actions:
Options in the Phase1 Proposal Configuration:
Option | Description |
Proposal Name |
Specifies or displays the name of the Phase1 proposal. |
Authentication |
Specifies the IKE identity authentication method. IKE identity authentication is used to verify the identities of both communication parties. There are two methods for authenticating identity: pre-shared key and RSA signature. The default value is pre-shared key. For pre-shared key method, the key is used to generate a secret key and the keys of both parties must be the same so that it can generate the same secret keys. |
Hash |
Specifies the authentication algorithm for Phase1. Select the algorithm you want to use.
|
Encryption |
Specifies the encryption algorithm for Phase1.
|
DH Group |
Specifies the DH group for Phase1 proposal.
|
Lifttime |
Specifies the lifetime of SA Phase1. The value range is 300 to 86400 seconds. The default value is 86400. Type the lifetime value into the Lifetime textbox. When the SA lifetime runs out, the device will send a SA P1 deleting message to its peer, notifying that the P1 SA has expired and it requires a new SA negotiation. |