Tunnel - Advanced |
Top Previous Next |
It is possible to set advanced options here if necessary. These option mostly are only necessary if you want to create VPN tunnels to third party gateways. If you connect two Gibraltar firewalls you need not change anything here.
Type: Choose the type of the IPSec tunnel from the option field Tunnel or Transport. The option Transport only works with host-to-host connections. Tunnel also works with host-to-subnet or subnet-to-subnet connections. IP compression: Mark this checkbox if you want to activate IP compression. If one of the end points of the tunnel deactivated this option, the transmission occurs uncompressed. PFS (perfect forward secrecy): Mark this checkbox if you want to activate an additional key management protocol, which regenerates the key of the encoding algorithm in temporary intervals. Thereby it's prevented that someone who cracks the key can encode information that he received for a longer time. Number of trials: Enter the times how often IPSec should try to establish the connection. If you enter the value 0 the number of trials is unlimited. Keylife (IKE - Phase 1): Enter the period how long the session keys of phase 1 are valid. After expiration of the term the session keys are negotiated again. Keylife (Phase 2): Enter the period how long the session keys of phase 2 are valid. After expiration of the term the session keys are negotiated again. Phase 1: Choose the IKE and Hash algorithms and the Diffie Hellman group (DH group) you want to use. Phase 2: Choose the ESP and Hash algorithms you want to use.
|