Configure an IKEv2 policy object
Use the IKEv2 policy dialog box to create, delete, and edit an IKEv2 policy object. These policy objects contain the parameters required for IKEv2 policies.
Procedure
Step 1 | Choose from the table of contents. Previously configured policies are listed including system defined defaults. Depending on your level of access, you may Edit ( |
Step 2 | Click Add IKEv2 Policy to create a new policy. Then, enter a Name for this policy. The policy object name can be up to 128 characters. Optionally, enter the description. The description can be up to 1024 characters. |
Step 3 | Enter the Priority. The priority value of the IKE proposal. The priority value determines the order of the IKE proposals compared by the two negotiating peers when attempting to find a common security association (SA). If the remote IPsec peer does not support the parameters selected in your first priority policy, it tries to use the parameters defined in the next lowest priority policy. Valid values range from 1 to 65535. The lower the number, the higher the priority. If you leave this field blank, Management Center assigns the lowest unassigned value starting with 1, then 5, then continuing in increments of 5. |
Step 4 | Enter the Lifetime of the security association (SA), in seconds. You can specify a value from 120 to 2,147,483,647 seconds. The default is 86400. When the lifetime is exceeded, the SA expires and must be renegotiated between the two peers. Generally, the shorter the lifetime (up to a point), the more secure your IKE negotiations. However, with longer lifetimes, future IPsec security associations can be set up more quickly than with shorter lifetimes. |
Step 5 | Select algorithms for these methods:
|
Step 6 | Click Save. If a valid combination of choices has been selected the new IKEv2 policy is added to the list. If not, errors are displayed and you must make changes accordingly to successfully save this policy. |

