TMS zl Management and Configuration Guide ST.1.1.100430
7-160
Virtual Private Networks
Configure an L2TP over IPsec VPN
12. For IKEv1 Policy, select the previously configured IKEv1 policy.
You must select a policy of the client-to-site type.
13. Leave the Enable PFS (Perfect Forward Secrecy) for keys check box clear.
14. For SA Lifetime in Seconds, leave the default 28800 (8 hours).
15. For SA Lifetime in Kilobytes, leave the default, 0.
Note You could configure other settings for PFS and the SA lifetimes. However, in
that case, you could not use the New Connection Wizard to set up the VPN
connection on the Windows client; instead, you would have to configure the
IPsec settings for the connection manually and make sure to match the
settings configured here.
16. Click Next.
17. Clear the Enable IP Address Pool for IRAS (Mode Config) check box.
Figure 7-134. Add IPsec Policy Window—Step 3 of 4
18. Click Next.