Azure Site to Site VPN required Device configuration parameters
Whether you Selected IKEv1 or IKEv2 the following settings needs to be configurable with the following values:
Methods of Encryption and Integrity
Two parameters are decided during the negotiation:
- Encryption algorithm
- Hash algorithm
Parameter |
IKE Phase 1 (IKE SA) |
IKE PHASE 2 (IPSec SA) |
---|---|---|
Encryption |
|
|
Integrity |
|
|
Diffie Hellman Groups
The Diffie-Hellman key computation (also known as exponential key agreement) is based on the Diffie Hellman (DH) mathematical groups. A Security Gateway supports these DH groups during the two phases of IKE.
Parameter |
IKE Phase 1 (IKE SA) |
IKE Phase 2 (IPSec SA) |
---|---|---|
Diffie Hellman Groups |
|
|
(Main mode is the required) vs aggressive mode
Perfect Forward Secrecy is Disabled
ESP (Encapsulating Security Payload) is required vs AH (Authentication Header)
Ref: https://sc1.checkpoint.com/documents/R77/CP_R77_VPN_AdminGuide/13847.htm