Field
Description
Block Time
Define how long a peer is blocked for tunnel setups after a
phase 1 tunnel setup has failed. This only affects locally initiated
setup attempts.
Possible values are
to
,+
(seconds);
means the
value in the default profile is used and
means that the peer is
never blocked.
The default value is
.
NAT Traversal
NAT Traversal (NAT-T) also enables IPSec tunnels to be
opened via one or more devices on which network address
translation (NAT) is activated.
Without NAT-T, incompatibilities may arise between IPSec and
NAT (see RFC 3715, section 2). These primarily prevent the
setup of an IPSec tunnel from a host within a LANs and behind
a NAT device to another host or device. NAT-T enables these
kinds of tunnels without conflicts with NAT device, activated
NAT is automatically detected by the IPSec Daemon and NAT-T
is used.
Only for
L6 .$ =-
Possible values:
•
;
(default value): NAT Traversal is enabled.
•
!-;
: NAT Traversal is disabled.
•
$3
: The device always behaves as it would if NAT were in
use.
Only for
L6 .$ =-
The function is enabled with
;
.
The function is enabled by default.
CA Certificates
Only for Phase-1 (IKE) Parameters
Only for Authentication Method =
! :$
,
:$
or
3$<.
If you enable the Trust the following CA certificates option,
you can select up to three CA certificates that are accepted for
this profile.
23 VPN
bintec elmeg GmbH
488
elmeg hybird 120 / hybird 130