HP VPN Firewall Appliances VPN Configuration Guide

148
3. Click Suite mode to configure an IPsec proposal that uses a pre-defined encryption suite.
Figure 109 IPsec proposal configuration in suite mode
4. Enter a name for the IPsec proposal.
5. Select an encryption suite for the proposal.
An encryption suite specifies the IP packet encapsulation mode, security protocol, and
authentication and encryption algorithms to be used. Available encryption suites include:
{ Tunnel-ESP-DES-MD5—Uses the ESP security protocol, the DES encryption algorithm, and the
MD5 authentication algorithm.
{ Tunnel-ESP-3DES-MD5—Uses the ESP security protocol, the 3DES encryption algorithm, and the
MD5 authentication algorithm.
{ Tunnel-AH-MD5-ESP-DES—Uses the ESP and AH security protocols successively, making ESP
use the DES encryption algorithm and perform no authentication and making AH use the MD5
authentication algorithm.
{ Tunnel-AH-MD5-ESP-3DES—Uses the ESP and AH security protocols successively, making ESP
use the 3DES encryption algorithm and perform no authentication, and making AH use the
MD5 authentication algorithm.
All these suites use the tunnel mode for IP packet encapsulation.
6. Click Apply.
Configuring an IPsec proposal in custom mode
1. From the navigation tree, select VPN > IPSec > Proposal to enter the IPsec proposal management
page, as shown in Figure 107.
2. Click Add to enter the IPsec proposal configur
ation wizard page, as shown in Figure 108.
3. Click Custom mode.
Figure 110 IPsec proposal configuration in custom m
ode
4. Configure the IPsec proposal parameters as described in Table 10.
5. Click Apply.