HP TMS zl Module Security Administrator's Guide

4-352
Configuring a VPN on the HP TMS zl Module
GRE Tunnels
Figure 4-261. Manage IPsec Wizard > Add IKEv1 Policy (step 2) Window
13. Under IKE Authentication, configure these settings:
a. For Key Exchange Mode, select Main Mode or Aggressive Mode.
The mode must match that configured on the remote endpoint. See
“IKE modes” on page 4-18 for guidelines.
b. For Authentication Method, select one of the following:
Preshared Key
DSA Signature
RSA Signature
If you select DSA Signature or RSA Signature, you can go directly to
step 14. (After you finish the IKEv1 policy, you must install certificates
as described in “Install Certificates Manually” on page 4-394 or “Install
Certificates Using SCEP” on page 4-418.)
If you want to use SCEP to install certificates, select RSA Signature
rather than DSA Signature.