Internet Key Exchange (IKE) IPsec Key Management for VPNs 6-15
•
Dead Peer Detection
toggles whether or not the Router will detect a remote peer being offline.
Enhanced Dead Peer Detection
Netopia Firmware Version 8.7 adds a new Dead Peer Detection mechanism.
In previous firmware versions, when Dead Peer Detection was enabled, a counter would begin in the router
when any traffic was sent through the tunnel. Determination of a dead peer could take up to eight minutes.
Netopia Firmware Version 8.7 provides a new Dead Peer Detection mechanism. An IPsec IP net inter face
sends ICMP ping requests to a specific IP address on a Remote Member network. The ping is periodic, and
the reply is expected within a cer tain amount of time. If the ICMP reply does not arrive within that time, the
peer is considered dead, the current phase 2 SAs are torn down, and the IKE SA star ts a new phase 1
negotiation, followed by the normal phase 2 negotiation, thereafter.
When you toggle
Dead Peer Detection
to
Yes
(on), new options appear.
•
Ping host
allows you to specify the host IP address of the host to ping, and from which replies will be
expected.
This field is only available if you have previously configured, and
committed
, remote network IP data in the
Add Network Configuration screen under Advanced IP Profile Options. See
“Add Network Configuration” on
page 6-17
.
•
Ping retry interval
and
Ping reply timeout
options appear.
The defaults are 5 seconds and 90 seconds, respectively. You may adjust these to suit your network’s
tolerances.
Advanced IPsec Options
SA Lifetime seconds: 28800
SA Lifetime Kbytes: 0
Perfect Forward Secrecy: Yes
Dead Peer Detection: Yes
Ping host: 1.1.1.1
Ping retry interval: 5
Ping reply timeout: 90
Summary of Contents for 3300-ENT Series
Page 10: ...x Firmware User Guide...
Page 16: ...1 6 Firmware User Guide...
Page 44: ...2 28 Firmware User Guide...
Page 96: ...3 52 Firmware User Guide...
Page 192: ...6 26 Firmware User Guide...
Page 264: ...9 14 Firmware User Guide...
Page 314: ...10 50 Firmware User Guide...
Page 324: ...11 10 Firmware User Guide...
Page 334: ...Index 6...