R3721-F3210-F3171-HP High-End Firewalls VPN Configuration Guide-6PW101

225
Item Descri
tion
Pre-Shared Key
Select the authentication method for IKE negotiation and specify the required
argument. Options include:
Pre-Shared Key—Uses the pre-shared key authentication method.
PKI Domain—Uses the RSA signature authentication method. Available PKI
domains are those configured by selecting VPN > Certificate Manager > Domain
from the navigation tree.
IMPORTANT:
If you select PKI Domain, an IKE proposal numbered 1 will be created.
PKI Domain
Enable DPD
Select this box to enable dead peer detection (DPD).
IMPORTANT:
If you enable DPD and the name of the IPsec VPN is abc, the wizard will create a DPD
named abc_dpd and apply it to peer abc_peer.
6. Click Next.
Figure 142 IPsec VPN policy configuration wizard: 4/4 (branch node)
7. Click Finish to complete the configuration.
The system will jump to the page that you can enter by selecting VPN > IPSec > IPSec Application
from the navigation tree.
Configuring a peer node
1. Select Peer Node from the first page of the IPsec VPN policy configuration wizard.
2. Click Next.