IPsec parameters
Digi TransPort User Guide
403
Inhibit this IPsec tunnel when IPsec tunnels n are up
A list of IPsec tunnels that can inhibit this IPsec tunnel from being used as long as they are up.
If this IPsec tunnel has been allowed to come up, and the IPsec tunnel that inhibits it comes
back up, this IPsec is taken down and any SAs that may have existed are removed. As soon as
an inhibiting IPsec tunnel goes down, the router will check to see if the inhibited IPsec tunnel
can now create SAs.
Inhibit this IPsec tunnel unless IPsec tunnel n is up
This IPsec tunnel will be inhibited unless specified IPsec tunnel is also up.
IKE negotiation source IP address is taken from the
Defines which IP address IKE uses as the source IP address during the negotiation.
Interface
Use the IP address of the interface over which the IKE packets will be transmitted.
Secondary IP address
Use the IP address configured in the Secondary IP address parameter on the
Configuration > Network > Advanced Network Settings
page.
Interface x,y
Use the IP address of the specified interface.
Tunnel this IPsec tunnel inside another IPsec tunnel
It is possible to tunnel packets from an IPsec tunnel within a second (or more) tunnel. When
this parameter is enabled.
NAT-Traversal Keepalive timer s seconds
Sets the interval period, in seconds, that the router will use to send regular packets to a NAT
device in order to prevent the NAT table entry from expiring.
Allow protocol IP protocol(s) in this tunnel
This restricts the type of IP packets that will be tunneled through the IPsec tunnel. The options
are:
• All
• TCP
• UDP
• GRE
IP packets with ToS values n must use this tunnel
Packets with matching ToS fields will only be tunneled through this IPsec tunnel and no others.
The usual traffic selector matching still takes place as normal. Packets that don’t have
matching ToS values will get tunneled as normal. Enter the ToS values as a comma separated
list, such as
2,4
.
Only tunnel IP packets with
Restricts the IP packets that will be tunneled to those with matching TCP/UDP port numbers.
local TCP/UDP port n
Allow IP packets with matching source TCP/UDP ports to be tunneled.