NB3711 User Manual 4.0
Parameter
IPsec General Settings
DPD Status
Specifies whether Dead Peer Detection (see RFC 3706) shall
be used. DPD will detect any broken IPSec connections, in
particular the ISAKMP tunnel, and refresh the correspond-
ing SAs (Security Associations) and SPIs (Security Payload
Identifier) for a faster re-establishment of the tunnel.
Detection cycle
The delay (in seconds) between DPD keepalives that are
sent for this connection (default 30 seconds)
Failure threshold
The number of unanswered DPD requests until the IPsec
peer is considered dead (the router will then try to re-
establish a dead connection automatically)
Action
The action to perform if a peer disconnects.
Available
choices from the drop-down menu are to clear, hold or to
Restart the peer.
IKE Authentication
NetModule routers support IKE authentication through pre-shared keys (PSK) or certifi-
cates within a public key infrastructure. Extended Authentication (XAUTH) leverages
RADIUS-like authentication and can be used to apply user level access control over
IPSec.
Using PSK requires the following settings:
Parameter
IPsec IKE Authentication Settings
PSK
The pre-shared key used to authenticate at the peer
Local ID Type
The type of identification for the local ID which can be a
FQDN
,
username@FQDN
or
IP address
Local ID
The local ID value
Local ID Type
The type of identification for the remote ID
Remote ID
The remote ID value
When using certificates you would need to specify the operation mode. When run as PKI
client (initiator) you can create a Certificate Signing Request (CSR) in the certificates
section which needs to be submitted at your Certificate Authority and imported to
the router afterwards. In PKI server mode (concentrator), the router represents the
Certificate Authority and issues the certificates for remote peers. They are revokable.
Using XAUTH the following settings can be made:
100
Summary of Contents for NB3711
Page 90: ...NB3711 User Manual 4 0 Figure 5 27 Inbound NAPT 90...
Page 92: ...NB3711 User Manual 4 0 Figure 5 29 OpenVPN Configuration 92...
Page 96: ...NB3711 User Manual 4 0 Figure 5 30 OpenVPN Client Management 96...
Page 98: ...NB3711 User Manual 4 0 Figure 5 31 IPsec Administration 98...
Page 104: ...NB3711 User Manual 4 0 Figure 5 34 PPTP Tunnel Configuration 104...
Page 114: ...NB3711 User Manual 4 0 Figure 5 37 SDK Administration 114...
Page 117: ...NB3711 User Manual 4 0 Figure 5 38 SDK Jobs 117...
Page 121: ...NB3711 User Manual 4 0 Figure 5 39 DHCP Server 121...
Page 131: ...NB3711 User Manual 4 0 Figure 5 44 SMS Configuration 131...
Page 158: ...NB3711 User Manual 4 0 Figure 5 55 Remote Authentication 158...
Page 162: ...NB3711 User Manual 4 0 Figure 5 57 Automatic File Configuration 162...
Page 166: ...NB3711 User Manual 4 0 Figure 5 59 Log Viewer 166...
Page 167: ...NB3711 User Manual 4 0 Figure 5 60 Tech Support File 167...
Page 175: ...NB3711 User Manual 4 0 5 9 LOGOUT Please use this menu to log out from the Web Manager 175...
Page 213: ...NB3711 User Manual 4 0 Event Description Table A 3 SDK Examples 213...
Page 214: ......