Fields in the Advanced Settings menu
Field
Description
Alive Check
Select the method to be used to check the functionality of the
IPSec connection.
In addition to the default method Dead Peer Detection (DPD),
the (proprietary) Heartbeat method is implemented. This sends
and receives signals every 5 seconds, depending on the config-
uration. If these signals are not received after 20 seconds, the
SA is discarded as invalid.
Possible values:
•
1%
(default value): Your device detects and uses
the mode supported by the remote terminal.
•
%
: Your device neither sends nor expects a heart-
beat. Set this option if you use devices from other manufactur-
ers.
•
8#& ?,% /)"
: Your device expects a
heartbeat from the peer, but does not send one itself.
•
-
: Your device expects no heartbeat from the peer, but
sends one itself.
•
8#& - J?,%"
: Your device expects a
heartbeat from the peer and sends one itself.
•
3 3%
: Use DPD (dead peer detection) in
accordance with RFC 3706. DPD uses a request-reply pro-
tocol to check the availability of the remote terminal and can
be configured independently on both sides. This option only
checks the availability of the peer if data is to be sent to it.
•
3 3% /"
: Use DPD (dead peer de-
tection) in accordance with RFC 3706. DPD uses a request-
reply protocol to check the availability of the remote terminal
and can be configured independently on both sides. This op-
tion is used to carry out a check at certain intervals depending
on forthcoming data transfers.
Block Time
Define how long a peer is blocked for tunnel setups after a
phase 1 tunnel setup has failed. This only affects locally initiated
setup attempts.
Possible values are
!
to
(seconds);
!
means the
value in the default profile is used and
means that the peer is
Funkwerk Enterprise Communications GmbH
18 VPN
R1xxx/R3xxx/R4xxx
295