That would be for an ipsec tunnel policy The link below may help. Phase 1
is also called main mode and phase 2 quick mode. Also Windows 2000 does not
support AES for ipsec. 3DES is the strongest it can use though if you have
an endpoint firewall device it might. --- Steve
http://support.microsoft.com/default...b;en-us;252735
"Miha" <(E-Mail Removed)> wrote in message
news:%(E-Mail Removed)...
> Hello
>
>
>
> In our company we need to establish a secure VPN channel with outside
> company in other country. They had already configured a VPN server
> (running on WinNT) and sent us the following information so we could
> configure a VPN client to connect.
>
>
>
> Authentication method: pre-share secret
>
> Key-change for encryption domain: yes
>
>
>
> IKE (phase 1):
>
> Encryption algorithm AES-256
>
> 'Condensation' function SHA-1
>
> Diffie Helman group: 1024 bit
>
>>Agressive mode< no
>
> Key lifetime for phase1 1440 min
>
>
>
> IKE (phase 2):
>
> Encryption algorithm AES-256
>
> 'Condensation' function SHA-1
>
>>Perfect Forward Secrecy enabled< no
>
> PFS DH group: 1024 bit
>
>>IP compression< no
>
>>IPSEC SA Lifetime< 3600 s
>
>
>
>
>
> I'm pretty confused of the information we got from them, because as far as
> I know this aren't settings that could normally be configure for a VPN
> client.
>
> Is this possible and how could be done or do we need to configure a
> site-site VPN tunnel to achieve that kind of functionality.
>
> I would be very thankful for all the information and tips how to do this
>
> Thank you all in advance
>
>
>
> Regards
>
> Miha
>
>