Configure remote access VPN IKE policies
Configure IKE policies to define the security parameters for IPsec negotiations in remote access VPN connections.
IKE is a key management protocol that authenticates IPsec peers, negotiates encryption keys, and automatically establishes IPsec SAs. IKE negotiation occurs in two phases:
-
Phase 1 — Establishes a secure security association between two IKE peers, enabling secure communication in Phase 2.
-
Phase 2 — Uses the Phase 1 SA to establish SAs for other applications, such as IPsec.
Both phases use proposals to negotiate a connection. An IKE proposal is a set of algorithms that two peers use to secure the negotiation. IKE negotiation begins with both peers agreeing on a common IKE policy that defines the security parameters for subsequent negotiations.
The IKE Policy table lists all the IKE policy objects applicable to the selected VPN configuration when Secure Client endpoints connect using the IPsec protocol.
Note | Firewall Threat Defense supports only IKEv2 for remote access VPNs. |
Procedure
Step 1 | Choose . |
Step 2 | Click the edit icon next to the remote access VPN policy. |
Step 3 | Click the Advanced tab. |
Step 4 | In the left pane, click IPsec > IKE Policy. |
Step 5 | Click + to select from the available IKEv2 policies, or add a new IKEv2 policy. |
Step 6 | Click OK. |
Step 7 | Click Save. |