Hi there, I currently setup a site-to-site Tunnel between our server-site and a remote off-site. The problem is that in contrary to Phase 1 (AES_SHA256) the remote router only supports DES (single DES) on Phase 2. Is it feasable to use insecure DES on phase 2 when Phase 1 is properly secured or should I replace the router? kind regards Clemens