Changing the Phase-1 Profiles

Go to the following menu to change the profile for phase-1:

  1. Go to VPN -> IPSec -> Phase-1 Profiles-> <Multi-Proposal> -> .

VPN -> IPSec -> Phase-1 Profiles-> <Multi-Proposal> ->

Relevant fields in the Phase-1 Profiles menu

Field Meaning
Description Define a name for the profile.
Proposal Defines the encryption and authentication algorithm to be used.
DH Group Defines the Diffie-Hellman group to be used.
Lifetime Defines the time or data volume after which re-authentication is carried out.
Authentication Method Select the authentication method.
Mode Defines the type of tunnel negotiation.
Local ID Type Defines the type of local ID for the gateway.
Local ID Value This is the local ID of the gateway.

Proceed as follows to change the profile for phase-1:

  1. Under Description enter the name of the profile, for example, Phase1 PSK .

  2. Under Proposal Encryption select 3DES , under Authentication select SHA1 in the first entry. Since at least one proposal must be configured at any one time, the first entry in the list is enabled by default.

  3. Leave DH Group set to 2(1024 Bit) .

  4. Under Lifetime Seconds enter a time in seconds, in this example 28800 and leave the KBytes set to 0 .

  5. Leave the Authentication Method set to Preshared Keys .

  6. Leave Mode set to Aggressive .

  7. Set the Local ID Type to IPV4 Address .

  8. Under Local ID Value enter the ID, in this example 192.168.1.254 .

Additional settings are required for the phase-1 configuration. For this, go to the following menu:

  1. Go to Phase-1 Profiles -> <Multi-Proposal>-> -> Advanced Settings.

Relevant fields in the menu Advanced Settings

Field Meaning
Alive Check Defines the type of phase monitoring.
NAT Traversal Determines whether or not the NAT traversal is used.

Proceed as follows:

  1. Under Alive check select Inactive .

  2. Deselect NAT Traversal.

  3. Confirm with OK.

Configure the phase 1 for the gateway in the branch in the same way.