What is the default proposal for Nebula-to-Nebula VPN on Nebula Security Gateway?

Zyxel_Irene
Zyxel_Irene Posts: 118  Zyxel Employee
5 Answers First Comment Friend Collector First Anniversary
edited August 2022 in Nebula Security Gateway

The default proposal for Nebula-to-Nebula VPN is as following:


[Nebula Security Gateway]

IKE version: IKEv1

Negotiation Mode: Main


Phase 1

-Encryption: 3DES

-Authentication: SHA256

-Diffie-Hellman group: DH1

-SA Lifetime (seconds): 84600

 

Phase 2

-Encryption: 3DES

-Authentication: SHA256

-PFS group: none

-Lifetime (seconds): 84600



[USG FLEX Series/ATP Series]

IKE version: IKEv2

Negotiation Mode: Main


Phase 1

-Encryption: AES128

-Authentication: SHA1(SHA128)

-Diffie-Hellman group: DH2

-SA Lifetime (seconds): 84600

 

Phase 2

-Encryption: AES128

-Authentication: SHA1(SHA128)

-PFS group: DH2

-Lifetime (seconds): 28800


Tagged: