Set up the IPsec tunnel Phase 1

Site A Configuration

In the VPN menu select IPsec. It opens on the Tunnels tab. Click the + button to create a new Phase 1 setup. (Make sure Enable IPsec is checked and saved.)

Enter these values:

FieldValueNotes
Internet ProtocolIPv4 
InterfaceWANUnless using a separate OPT interface
DescriptionSite BThe site’s locality or another suitable description
Authentication methodMutual PSK 
Negotiation modeaggressive 
My identifierMy IP address 
Peer identifierPeer IP address 
Pre-Shared KeyA long key.This can be generated using external utilities but be careful to copy it without extra spaces.
Policy      Genera- tionDefault 
Proposal Check- ingDefault 
Encryption algo- rithmAES 256bitsRead this comparison of encryption algorithms.
Hash algorithmSHA256Read this comparison of hash algorithms.
DH key group2 (1024 bit)Read this explanation of Perfect forward secrecy.
Lifetime28800 
NAT TraversalDisableTurn this off unless it is definitely needed.
Dead Peer Detec- tionEnable: 10 seconds, 5 retriesLeave this on unless the other side does not properly support DPD.

Note that the Phase 1 entry is now shown on the IPsec page. Click Save and in the next screen click Apply Changes.

Site B Configuration

Do the same as in Site A but in the Remote Gateway field enter Site A’s public IP address or FQDN and in the

Description field enter ‘Site A’.