Field
Description
accordance with RFC 3706. DPD uses a request-reply pro-
tocol to check the availability of the remote terminal and can
be configured independently on both sides. This option only
checks the availability of the peer if data is to be sent to it.
•
- -* "+#
: Use DPD (dead peer de-
tection) in accordance with RFC 3706. DPD uses a request-
reply protocol to check the availability of the remote terminal
and can be configured independently on both sides. This op-
tion is used to carry out a check at certain intervals depending
on forthcoming data transfers.
Only for Phase-1 (IKEv2) Parameters
Enable or disable alive check.
The function is enabled by default.
Block Time
Define how long a peer is blocked for tunnel setups after a
phase 1 tunnel setup has failed. This only affects locally initiated
setup attempts.
Possible values are
to
(seconds);
means the
value in the default profile is used and
means that the peer is
never blocked.
The default value is
. If a peer has been configured in "al-
ways up" mode, there is an implicit minimum block time of 15
seconds which is aplied independently from the configured
value.
NAT Traversal
NAT Traversal (NAT-T) also enables IPSec tunnels to be
opened via one or more devices on which network address
translation (NAT) is activated.
Without NAT-T, incompatibilities may arise between IPSec and
NAT (see RFC 3715, section 2). These primarily prevent the
setup of an IPSec tunnel from a host within a LANs and behind
a NAT device to another host or device. NAT-T enables these
kinds of tunnels without conflicts with NAT device, activated
NAT is automatically detected by the IPSec Daemon and NAT-T
is used.
Only for
= 1+
14 VPN
bintec elmeg GmbH
258
be.IP 4isdn