Add an L2TP IPSec Phase 1 Transform
L2TP has three default Phase 1 transform sets:
- SHA1-AES256-DH2
- SHA1-AES256-DH20
- SHA2(256)-AES256-DH14
When the tunnel is created, the Firebox can use any of these transforms to match the transform set of the other VPN endpoint.
You can add more transform sets up to a maximum of nine. For example, you could add SHA1-AES128-DH2. The Firebox would then have four transform sets. The transform set at the top of the list is used first.
In Fireware v12.10 and higher, Fireware supports Diffie-Hellman Group 21.
- (Fireware v12.3 or higher) Select VPN > Mobile VPN.
- In the L2TP section, click Configure.
The Mobile VPN with L2TP configuration appears. - (Fireware v12.2.1 or lower) Select VPN > Mobile VPN with L2TP > Configure.
The Mobile VPN with L2TP configuration appears. - Select the IPSec tab.
- Select the Phase 1 Settings tab.
- In the Transform Settings section, click Add.
The Transform Settings dialog box appears.
- From the Authentication drop-down list, select MD5, SHA1, SHA2-256, SHA2-384, or SHA2-512 as the authentication method. Tip!
- From the Encryption drop-down list, select AES (128-bit), AES (192-bit), AES (256-bit), DES, or 3DES as the type of encryption. Tip!
- To change the security association (SA) life, type a number in the SA Life text box, and select Hour or Minute from the adjacent drop-down list. The SA life must be a number smaller than 596,523 hours or 35,791,394 minutes.
- From the Key Group drop-down list, select a Diffie-Hellman group. Fireware supports groups 1, 2, 5, 14, 15, 19, 20, and 21.
Diffie-Hellman groups determine the strength of the master key used in the key exchange process. A higher group number provides greater security, but more time is required to make the keys. For more information, go to About Diffie-Hellman Groups. - Click OK.
- Repeat Steps 5–10 to add more transforms. The transform set at the top of the list is used first.
- To change the priority of a transform set, select the transform set and click Up or Down.
- Click Save.
- Select VPN > Mobile VPN > L2TP.
- Select the IPSec tab.
- Select the Phase 1 Settings tab.
- In the Transform Settings section, click Add.
The Phase 1 Transform dialog box appears
- From the Authentication drop-down list, select MD5, SHA1, SHA2-256, SHA2-384, or SHA2-512 as the authentication method. Tip!
- From the Encryption drop-down list, select AES (128-bit), AES (192-bit), AES (256-bit), DES, or 3DES as the type of encryption. Tip!
- To change the SA (security association) life, type a number in the SA Life text box, and select Hour or Minute from the adjacent drop-down list. The SA life must be a number smaller than 596,523 hours or 35,791,394 minutes.
- From the Key Group drop-down list, select a Diffie-Hellman group. Fireware supports groups 1, 2, 5, 14, 15, 19, 20, and 21.
Diffie-Hellman groups determine the strength of the master key used in the key exchange process. A higher group number provides greater security, but more time is required to make the keys. For more information, go to About Diffie-Hellman Groups. - Click OK.
- Repeat Steps 4–9 to add more transforms. The transform set at the top of the list is used first.
- To change the priority of a transform set, select the transform set and click Up or Down.
- Click OK.