Configuring VPN
IPSec Policy
Cisco SRP500 Series Services Ready Platforms Administration Guide (SRP520 Models)
185
7
IPSec Policy
Use the IPSec Policy page to configure a VPN IPSec Policy. The IPSec VPN policy
contains the IPSec Security Association parameters, which define the connection
type and key type.
STEP 1
Click
VPN > Site to Site IPSec VPN > IPSec Policy
. The
IPSec Policy
window
opens.
From this page you can view the existing IPSec policies, edit an IPSec policy and
add an IPSec policy. You can also view the details for each policy from the IPSec
Details list.
STEP 2
To add an IPSec policy, click
Add
Entry
. The
IPSec Policy
window opens.
STEP 3
To enable the new policy, select
Enable
.
STEP 4
Choose a policy identification number from the drop-down list.
STEP 5
In the
Policy Name
field, enter a unique name for the IPSec policy.
Enable Dead Peer
(DPD) Detection
To enable DPD, select
Enable
. The default is disabled.
NOTE
DPD is not required for an IKE rule, but if enabled,
helps to keep the connection alive during times when there is
no traffic.
DPD Interval
Enter an interval for DPD. This packet is sent periodically
in interval seconds during no data traffic.
DPD Timeout
Enter a timeout (in seconds) for Dead Peer Detection
(DPD).
Extended Authentication
XAUTH Client
Enable
Enable if the VPN peer requires Extended
Authentication credentials. The default setting is
disabled.
Username/
Password
Enter the credentials that the SRP uses to connect with
the remote peer.
IKE Policy Settings
Field
Description