![Black Box LS1016A User Manual Download Page 403](http://html.mh-extra.com/html/black-box/ls1016a/ls1016a_user-manual_2763435403.webp)
Appendix G - IPSEC
User Guide
403
Parameters are optional unless marked “required.” The currently-accepted
parameter
names
in a
config setup
section are:
Recommended Configuration
Certain parameters are now strongly-recommended defaults, but cannot (yet) be made sys-
tem defaults due to backward compatibility. Recommended config setup parameters are:
•
plutoload=%search
•
plutostart=%search
In practice, it is preferable to use the auto parameter to control whether a particular connec-
tion is added or started automatically.
Recommended
conn
parameters (mostly for automatic keying, as manual keying seldom sees
much use) are:
IPsec Usage
This section will teach you:
•
How to start and stop the IPsec daemon.
•
How to add and remove an IPsec connection from the IPsec database.
•
How to start and stop a connection.
keyingtries=0
Unlimited retries are normally appropriate for VPN connec-
tions. Finite values may be needed for Road Warrior and other
more ephemeral applications, but the fixed small default is
pretty much useless.
disablearrivalcheck=no
Tunnel-exit checks improve security and do not break any nor-
mal configuration.
authby=rsasig
Digital signatures are superior in every way to shared secrets.