Because the wizard creates a standard connection that can be used
for most VPN configurations, you will need to update the policies that were
generated by the wizard to ensure interoperability with Windows® XP
clients. To update these VPN policies, complete the following tasks:
- In iSeries™ Navigator,
expand .
- Double-click Internet Key Exchange Policies and
right-click Any IP address and select Properties.
- On the Transform page, click Add.
- On the Add Internet Key Exchange Transform page, select
the following options::
- Authentication method: Pre-shared key
- Hash algorithm: MD5
- Encryption algorithm: DES-CBC
- Click OK.
- In iSeries Navigator,
expand .
- Double-click Data Policies and right-click SalestoRemote and
select Properties.
- On the General page, clear Use Diffie-Hellman perfect forward
secrecy.
- On the Proposal page, click Add.
- On the New Data Policy Proposal page, select the following options:
- Encapsulation mode: Transport
- Key expiration: 15 minutes
- Expire at size limit: 100000
- On the Transform page, click Add.
- On the Add Data Policy Transform page, select the following
options:
- Protocol: Encapsulating security payload (ESP)
- Authentication algorithm: MD5
- Encryption algorithm: DES-CBC
- Click OK.