Set up the IPsec tunnel Phase 2

Site A Configuration

Click + under the Phase 1 entry. It will show an overview of all available Phase 2 entries. Since we haven’t made any yet none are shown.

Click  + to create a new Phase 2.

Enter these values:

FieldValueNotes
ModeTunnel IPv4 
Local NetworkType:    LAN  subnet.     NAT/BINAT type: None. 
Remote Network0.0.0.0/0This tells AZTCO-FW to route everything over this interface.
DescriptionSite B 
ProtocolESP 
Encryption     algo- rithmAES 256 bits 
Hash algorithmSHA256 
PFS key group2 (1024 bit) 
Lifetime3600 
Automatically ping hostEnter a hostname or IP address to keep the tunnel alive.In my experience this is not necessary.

Click Save and on the next page click Apply Changes.

Site B Configuration

Remote Network, Type: Network Local Network, Address: 0.0.0.0/0 Remote Network, Address: Site A’s LAN subnet Use the same Phase 2 proposal and Advanced options as in Site A.

Click Save and then Apply Changes.