Viper SC+™ IP Router for Licensed Spectrum PN 001-5008-000 Rev. C
| Page 111
Notes:
The Idle Timeout setting must be non-zero before Idle Probes are sent.
The retry frequency of each probe attempt is determined by the Network Latency setting.
For a Network Latency of 10, the probe frequency is 10 seconds.
Default = 3 seconds
Minimum = 0 seconds (disabled)
Maximum = 10 seconds
Key Timeout
(Available on VPN servers only.)
Maximum duration of VPN tunnel cipher keys. Key exchange consists of approximately twelve (12) 80-100 byte TCP
packets (1 kilobyte), which may take several seconds — or longer when the network is busy.
Notes:
The retry frequency of each key exchange attempt is determined by the Network Latency setting.
For a Network Latency of 10, the exchange attempt frequency is 0-70 seconds.
A VPN server automatically sets this parameter on its clients during key exchange.
Default = 6 hours
Minimum = 1 hour
Maximum = 24 hours
Network Latency
(Available on VPN servers only.)
This parameter is a factor (multiplier) for tuning VPN maintenance operations. It affects the frequency of server
status packets, idle probes, and key exchange retries (see explanations of these settings, earlier, for details).
This number should be set higher if key exchanges are occurring more frequently than the Key Timeout setting
(see the VPN Status and Statistics section.
Notes:
Only change this value by small amounts (1-5 seconds).
Default = 10 seconds
Minimum = 2 seconds
Maximum = 30 seconds
VPN Configuration – Client Settings
Server IP Addresses
(Available on VPN clients only.)
The IP address(es) of one or more VPN servers.
Note:
When the VPN Server Status Frequency setting is zero (default), each of its clients must be set with that
server’s RF IP address. Otherwise, this is optional (clients will “discover” the server’s IP address.
VPN Configuration – Packet Filter Settings
These filters provide criteria used to select which packets are sent via VPN tunnels. Packets passing inside VPN tunnels
are protected with strong encryption. Traffic not matching these filters is discarded when the Block non-VPN Traffic is
enabled (default). Otherwise, it is forwarded as-is (unencrypted.
Note:
Appropriate filters are automatically set when selecting the Set Client/Server Defaults buttons..
Source/Destination IP Address
and
Netmask
The source and destination IP addresses are used to select which packet are sent via VPN tunnels.
Source IP filter
Controls which traffic from the VPN device or its immediate Ethernet LAN enters the VPN.