User's Manual

Table Of Contents
WavePoint 10e
54. Enter the SA Lifetime time or amount of data value, and select which measure to use.
This defines the amount of time, in seconds, or the amount of data allowed to pass, in
Kbytes, for which the Security Association remains effective.
Note: When configuring a Lifetime in kilobytes (also known as lifebytes), be aware
that two SAs are created for each policy. One SA applies to inbound traffic,
and one SA applies to outbound traffic. Due to differences in the upstream
and downstream traffic flows, the SA may expire asymmetrically.
Example: If the downstream traffic is very high, the lifebyte for a download
stream may expire frequently. The lifebyte of the upload stream may not expire as
frequently. It is recommended that the values be reasonably set, to reduce the
difference in expiry frequencies of the SAs; otherwise the system may eventually
run out of resources as a result of this asymmetry. The lifebyte specifications are
generally recommended for advanced users only.
55. Set the Encryption Algorithm option to On to enable an Encryption Method.
56. Select an Encryption Method to encrypt the data.
Note: If BLOWFISH is selected, it requires a Key Length in a multiple of 8
between 40 and 448.
If CAST128 is selected, it requires a Key Length in a multiple of 8 between
40 and 128.
57. Set the Integrity Algorithm option to On to enable Integrity Algorithm.
58. Select one Integrity Algorithm to verify the integrity of the data.
59. Select one PFS (Perfect Forward Secrecy) Key Group.
This ensures a Diffie-Hellman exchange is performed for every phase-2 negotiation.
Note: This selection will cause the WavePoint 10e to run slower.
Configure Phase 2 Manual Policy Parameters
Complete this additional information in the Phase 2 (Manual Policy Parameters) section for the
Phase 2 Manual Policy Parameters.
60. Enter a SPI - Incoming hexadecimal value between 3 and 8 characters.
The value must match the remote VPN endpoint’s Outgoing value.
61. Enter a SPI - Outgoing hexadecimal value between 3 and 8 characters.
The value must match the remote VPN endpoint’s Incoming value.
62. Select one Encryption Algorithm to encrypt the data.
LUM0063AA Rev 05/05/2014 Page 117 of 171
This document is the property of FreeWave Technologies, Inc. and contains proprietary information owned by
FreeWave®. This document cannot be reproduced in whole or in part by any means without written permission from
FreeWave Technologies, Inc.