Configure an IKEv2 IPsec proposal object
Use this task when you need to define or update the cryptographic settings for IKEv2 IPsec VPN tunnels on your Secure Firewall Management Center. This is relevant when setting up new VPNs or adjusting security policies to meet organizational requirements.
Procedure
Step 1 | Choose from the table of contents. Previously configured proposals are listed including system defined defaults. Depending on your level of access, you may Edit ( | ||
Step 2 | Choose Add IKEv2 IPsec Proposal to create a new proposal. | ||
Step 3 | Enter a Name for this proposal. The policy object name can be up to 128 characters. | ||
Step 4 | Enter a Description for this proposal. The policy object description can contain up to 1,024 characters. | ||
Step 5 | Click ESP Hash, the hash or integrity algorithm to use in the proposal for authentication.
For IKEv2, select all the options you want to support for ESP Hash. For a full explanation of the options, see Decide which hash algorithms to use. | ||
Step 6 | Click ESP Encryption . Select the Encapsulating Security Protocol (ESP) encryption algorithm for this proposal. For IKEv2, click Select to open a dialog box where you can select all of the options you want to support. When deciding which encryption and hash algorithms to use for the IPsec proposal, choose only algorithms supported by the devices in the VPN. For a full explanation of the options, see Decide encryption algorithms for VPN policies. | ||
Step 7 | Click Save. The new proposal is added to the list. |

