5. If you wish to work in IKE aggressive mode, use the
initiate mode
aggressive
command.
Note:
Aggressive mode is one of the prerequisites for working with dynamic local peer
IP addresses. For more information about working with dynamic local peer IP
addresses, see
on page 509.
For example:
Gxxx-001(config-peer:149.49.70.1)# initiate mode aggressive
Done!
6. If you want to listen in to communication from a remote peer that has a dynamic IP
address, use the
initiate mode none
command.
In this mode, the device can only accept inbound IKE Aggressive Mode connections
from the peer, and is not able to initiate IKE phase-1 (Main Mode or Aggressive
Mode) to the peer, nor is the peer able to participate as part of a peer-group. In
addition, specifying the
continuous-channel
command when configuring the
crypto ISAKMP peer information has no effect in this mode. For more information
on continuous-channel, see
7. Specify the branch device (Branch Gateway) by its address or by the FQDN name
that identifies the Branch Gateway in the remote peer, using the
self-
identity
command.
Note:
Specifying self-identity as a name is one of the prerequisites for working with
dynamic local peer IP addresses. For more information about working with
dynamic local peer IP addresses, see
For example:
Gxxx-001(config-peer:149.49.70.1)# self-identity address
Done!
Gxxx-001(config-peer:149.49.70.1)# self-identity fqdn vpn.avaya.com
Done!
8. Enable Dead Peer Detection (DPD) keepalives that check whether the remote peer
is up using the
keepalive
command, followed by the number of seconds between
DPD keepalive probes, and the number of seconds between retries if keepalive
fails.
The following example sets DPD keepalive to send probes every 10 seconds, and
to send retries every two seconds if DPD keepalive fails.
Gxxx-001(config-peer:149.49.70.1)# keepalive 10 retry 2
Done!
9. Bind peer status to an object tracker that can monitor hosts inside the remote peer’s
protected network.
IPSec VPN
Administering Avaya G430 Branch Gateway
October 2013 491
Summary of Contents for G430
Page 1: ...Administering Avaya G430 Branch Gateway Release 6 3 03 603228 Issue 5 October 2013 ...
Page 12: ...12 Administering Avaya G430 Branch Gateway October 2013 ...
Page 246: ...VoIP QoS 246 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Page 556: ...IPSec VPN 556 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...