MoRoS GPRS 2.1 PRO
Functions
In order to mask the received packets with the local IP address of the
MoRoS GPRS 2.1 PRO, check the checkbox "Mask packets through tun-
nel". The recipient of the packets will see the local IP address of the Mo-
RoS GPRS 2.1 PRO as sender than, not the address of the original sender
from the local net of the remote terminal.
In order to configure the dead peer detection, enter the interval, which is
used to send requests to the remote terminal, in seconds into the field
"Dead peer detection interval" and the maximum time, in which these re-
quests must be replied, in seconds into the field "Dead peer detection
timeout". Select the behaviour for a connection, which is considered as in-
terrupted, in the drop-down list "Action on dead peer". If you select "re-
start" (default setting) here, the connection will be restarted, for "clear", it
will be terminated, and for "hold", it will be held.
In order to enable perfect forward secrecy, check the checkbox "Activate
perfect forward secrecy". This can prevent that the next key can be dis-
covered more quickly from a hacked encryption. Both remote terminals
must have matching settings to be able to establish the connection.
In order to configure the interval for the key renegotiation, enter the value
in seconds into the field "Interval for renegotiation of data channel key".
The minimum value is 3600 seconds (1 hour). The regular renewal of the
used keys can ensure the security of the IPsec connection for a longer pe-
riod.
in order to send an additional ping via ICMP protocol to an IP address, en-
ter this address, which must be located in the local subnet of the remote
terminal, into the field "Additional ICMP ping to". If the ping is not suc-
cessful, a possibly existing tunnel will be terminated, and a new tunnel
will be established. The ping interval is 15 minutes.
In order to configure the authentication for an IPsec connection, select ei-
ther the radio button "Authentication based on certificates" or the radio
button "Authentication with pre shared key (PSK)“. The authentication
with certificates can be used for the main mode. It is indicated under the
option here, whether the individual certificates and keys are present
(green checkmark) or not (red cross). Present certificates can also be
downloaded (blue arrow) or deleted again (red cross on white box). The
private key can only be deleted. The authentication with passphrase can
be used for main mode and aggressive mode. The passphrase, which
must be used by all IPsec participants, must be entered into the field be-
low the option for this.
In order to confirm all settings for the loaded tunnel made above, click on
"OK".
In order to upload a certificate or key, click in the section "Upload key or
certificates" on the "Browse..." button. Then, select in the "Upload file"
window the desired file on the respective data carrier and click on the
"Open" button. If the file is encrypted, you must also enter the password
into the "Password (only with encrypted file)" field. Click on "OK" then to
upload the file.
81
Summary of Contents for MoRoS GPRS 2.1 PRO
Page 1: ...Manual MoRoS GPRS 2 1 PRO...
Page 2: ......
Page 82: ...Functions MoRoS GPRS 2 1 PRO 82...
Page 144: ......