InGateway Documentation, Release 0.0.1
· ICMP Detection Local IP: specifies the source address of the traffic to be protected by
IPsec.
· ICMP Detection Interval: specifies the interval between ICMP probe packets sent from
the local device.
· ICMP Detection Timeout: specifies the timeout period of an ICMP probe. If the local
device does not receive any ICMP Reply packet within this period, it considers that the
ICMP probe times out.
· ICMP Detection Max Retries: specifies the maximum number of retries after an ICMP
probe failure. (The local device restarts the IPsec service when the number of retries
reaches this value.)
4.4.1.2 IPsec Extension Setting
The IPsec extension parameters are described as follows:
• Basic Parameters
–
Name: specifies the name of an IPsec profile.
–
IKE Version: specifies the version of the IKE protocol. Options are IKEv1 and IKEv2.
–
IKEv1 Policy: specifies a policy ID defined in the IKEv1 policy list.
–
IKEv2 Policy: specifies a policy ID defined in the IKEv2 policy list.
–
IPsec Policy: specifies a policy ID defined in the IPsec policy list.
–
Authentication Type: specifies the authentication method used for the IPsec tunnel. Shared key
authentication and digital certificate authentication are supported.
* Shared Key: specifies the shared key used for authentication.
* Digital Certificate: specifies the digital certificate used for authentication. You need to
import a valid certificate on the certificate management page.
–
Negotiation Mode: specifies the mode of IKEv1 negotiation.
* Main Mode: separates key exchange information from the identity information. This mode
protects identity information to enhance the security.
* Aggressive Mode: does not provide identity authentication but meets requirements of some
special network environments. The aggressive mode can be used when the address of the
tunnel initiator cannot be obtained in advance or keeps changing, but both parties want to
establish an IKE SA by using a pre-shared key.
• IKE Advance (Phase 1)
–
Local ID: specifies the local ID of the specified type.
1.2. InGateway902 User Manual
103
Summary of Contents for InGateway501
Page 1: ...InGateway Documentation Release 0 0 1 zhangning Aug 24 2020...
Page 2: ......
Page 4: ...ii...