Virtual Private Networks (VPN)
IPsec
IX20 User Guide
284
v. Set the type of Diffie-Hellman group to use for key exchange during phase 2:
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)> dh_
group
value
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)>
where
value
is one of
ecp384
,
modp768
,
modp1024
,
modp1536
,
modp2048
,
modp3072
,
modp4096
,
modp6144
, or
modp8192
, . The default is
modp1024
.
vi. (Optional) Add additional phase 2 proposals:
i. Move back one level in the schema:
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)>
..
(config vpn ipsec tunnel ipsec_example ike phase2_proposal)>
ii. Add an additional proposal:
(config vpn ipsec tunnel ipsec_example ike phase2_proposal)> add
end
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 1)>
Repeat the above steps to set the type of encryption, hash, and Diffie-Hellman
group for the additional proposal.
iii. Repeat to add more phase 2 proposals.
16. (Optional) Configure dead peer detection:
Dead peer detection is enabled by default. Dead peer detection uses periodic IKE transmissions
to the remote endpoint to detect whether tunnel communications have failed, allowing the
tunnel to be automatically restarted when failure occurs.
a. Change to the root of the configuration schema:
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)> ...
(config)>
b. To disable dead peer detection:
(config)> vpn ipsec tunnel ipsec_example dpd enable false
(config)>
c. Set the number of seconds between transmissions of dead peer packets. Dead peer
packets are only sent when the tunnel is idle. The default is
60
.
(config)> vpn ipsec tunnel ipsec_example dpd delay
value
(config)>
d. Set the number of seconds to wait for a response from a dead peer packet before
assuming the tunnel has failed. The default is
90
.
(config)> vpn ipsec tunnel ipsec_example dpd timeout
value
(config)>
17. (Optional) Create a list of destination networks that require source NAT: