![InHand InGateway502 User Manual Download Page 95](http://html1.mh-extra.com/html/inhand/ingateway502/ingateway502_user-manual_2061305095.webp)
91
▪
IPsec SA Lifetime: specifies the duration in which the IPsec SA is alive. When
the two ends perform IPsec negotiation to establish an SA, the smaller value
between the lifetime values set on the local and peer devices takes effect.
▪
IPsec SA Idletime: specifies the maximum idle duration of an IPsec SA. If no
data is transmitted within this duration after the IPsec SA is established, the
IPsec SA becomes invalid. When the current IPsec SA is about to expire, IPsec
negotiation is triggered to establish a new SA, so that the new SA is ready
before the old SA becomes invalid.
o
Tunnel Advance
▪
Tunnel Start Mode: specifies how the IPsec tunnel is initiated.
•
Automatically: indicates that the local device completes IKE negotiation
automatically to set up an IPsec tunnel after the IPsec policy is applied. This
mode is often used on a client.
•
Respond Only: indicates that local device only receives IPsec requests and
does not initiate a connection. This mode is often used on a server.
•
On-demand: indicates that the local device completes IKE
negotiation to set up an IPsec tunnel only when detecting IPsec
packets on the interface.
▪
Local/Remote Send Cert Mode: specifies when to send the certificate. Options
are Send cert always, Send cert on request, and Not send cert.
•
Send cert always: Some IPsec services do not send certificate requests but
need to receive the certificate from the peer because they do not save the
certificate. For these IPsec services, you must select this option on the peer to
enable the IPsec tunnel to be established.
•
Send cert on request: The local device sends the certificate to the peer only
when receiving a request from the peer.
•
Not send cert: The local device sends the certificate to the peer regardless of
whether the peer sends a request.
▪
ICMP Detect
•
ICMP Detection Server: specifies the address of the peer host to be detected.
•
ICMP Detection Local IP: specifies the source address of the traffic to be
protected by IPsec.
•
ICMP Detection Interval: specifies the interval between ICMP probe packets
sent from the local device.
Summary of Contents for InGateway502
Page 1: ......
Page 8: ...4 2 2 Structure and Dimensions Figure 2 2 1 Wall Mounting A Figure 2 3 2 Wall Mounting B...
Page 48: ...44 The following figure shows the configuration of an extended access control policy...
Page 49: ...45 The following figure shows the configuration of an access control list...
Page 58: ...54 Once enabled the App automatically runs and will run every time the IG502 is started...
Page 62: ...58 After the update is completed as shown below...
Page 71: ...67...