The DH group used in IKE phase 1 for initial SA. Valid options are DHGroup1, DHGroup14, DHGroup2, DHGroup2048, DHGroup24, ECP256, ECP384, or None.
DHGroup1
DHGroup14
DHGroup2
DHGroup2048
DHGroup24
ECP256
ECP384
None
The IKE encryption algorithm. Valid options are AES128, AES192, AES256, DES, DES3, GCMAES128, or GCMAES256.
AES128
AES192
AES256
DES
DES3
GCMAES128
GCMAES256
The IKE integrity algorithm. Valid options are GCMAES128, GCMAES256, MD5, SHA1, SHA256, or SHA384.
MD5
SHA1
SHA256
SHA384
The IPSec encryption algorithm. Valid options are AES128, AES192, AES256, DES, DES3, GCMAES128, GCMAES192, GCMAES256, or None.
GCMAES192
The IPSec integrity algorithm. Valid options are GCMAES128, GCMAES192, GCMAES256, MD5, SHA1, or SHA256.
The DH group used in IKE phase 2 for new child SA. Valid options are ECP256, ECP384, PFS1, PFS14, PFS2, PFS2048, PFS24, PFSMM, or None.
PFS1
PFS14
PFS2
PFS2048
PFS24
PFSMM
The IPSec SA payload size in KB. Must be at least 1024 KB. Defaults to 102400000 KB.
1024
102400000
The IPSec SA lifetime in seconds. Must be at least 300 seconds. Defaults to 27000 seconds.
300
27000