HP TMS zl Module Security Administrator's Guide

4-237
Configuring a VPN on the HP TMS zl Module
Configuring an IPsec Site-to-Site VPN with Manual Keying
Figure 4-160. Manage IPsec Wizard > Add IPsec Proposal Window
4. In the Add IPsec Proposal window, type a descriptive string of 1 to 32
alphanumeric characters for Proposal Name. The string must be unique to
this proposal.
Often, it is a good idea to indicate the algorithms that you will select in
the name—for example, ESP3desMD5.
5. For Encapsulation Mode, typically select Tunnel Mode.
Tunnel mode allows endpoints behind the TMS zl Module and the remote
gateway to forward traffic over the VPN. In transport mode, traffic must
be originated by the TMS zl Module itself or by the remote gateway. This
mode is typically used when you are creating a proposal for GRE over
IPsec site-to-site VPNs or L2TP over IPsec client-to-site VPNs.
6. For Security Protocol, select AH or ESP.
7. If you selected ESP in the previous step, select one of the following for
Encryption Algorithm:
NULL
If you select this option, VPN traffic will not be encrypted.