Expand all | Collapse all
Create an IPsec Profile
To create an IPsec Profile:
A wizard
for adding an IPsec profile will display.
Define a
name
and
description
,
and click
Next
.
Edit the
IKE settings
of the IPsec
profile.
Key
Exchange
should be set to
IKEv2
.
IKEv1 is also supported.
DH Group
should be set to
MODP-1024
.
Encryption
should be set to
AES-256
.
Hash
should be set to
SHA-1
.
Edit the
ESP Group
settings.
Encapsulation
should
be set to
Force UDP
At the
Proposals
section, there should
be 1 proposal with the following settings:
DH
Group
should be set to
None
Encryption
should be set to
AES-256
Hash
should be set to
SHA-1
Edit the
Authentication
settings.
Type
should
be set to
PSK
.
Secret
should be set to the pre-shared
key of the Check Point Site that you copied at the previous steps.
Local ID type
should be set to Interface
IP Address
Click
Next
, review the settings
of the profile, then click
Save & Exit
.