776
IPSec
N0008589 3.3
5
Click the
Save
button.
Rekey Timeout
Allows you to specify the amount of time you can use a key before the tunnel is re-negotiated.
You should limit the lifetime of a single key used to encrypt data or else you will compromise
the effectiveness of a single session key. Use the Rekey Timeout setting to control how often
new session keys are exchanged between servers. You cannot set the Rekey Timeout setting
to less than three minutes, except to disable the timeout by entering 00:00:00.
Enter a value from 00:03:00 to 23:59:59. The default setting is 08:00:00.
A setting of 00:00:00 disables the Rekey Timeout setting.
Rekey Data Count
Allows you to specify the amount of data you can transmit on the tunnel before the tunnel is
re-negotiated.
Enter a value from 0 to 1000000 Kbytes.
A setting of 0 disables the Rekey Data Count.
Note
: If you set the Rekey Data Count too low, the tunnel is re-negotiated too often and will
consume extra system resources.
Local Endpoint
Allows you to specify the IP address of the interface on Business Communications Manager
that is the entrance or exit of the IPSec tunnel.
Enter the IP address in the dotted format.
Remote Endpoint
Allows you to specify the IP address of the remote IPSec gateway that is the entrance or exit of
the IPSec tunnel.
Enter the IP address in the dotted format.
Note
: Different tunnels cannot have the same Remote Endpoint. This includes PPTP tunnels.
Send All Traffic
Through IPSec
Tunnel
Select
Yes
if you want all data traffic to be sent through this IPSec tunnel.
Select
No
if you do not want all traffic to use this IPSec tunnel.
When you select Yes to enable this option, any existing accessible networks for this Branch
Office account are saved. If you choose No later, then these saved accessible networks are
restored.
When a Branch Office account has this option enabled, then all other Branch Office and
Remote User tunnels are disabled since all traffic will go through this tunnel. In addition, no
other Branch Office or Remote User tunnels can be created while this option is enabled.
The default setting is No.
Create Firewall
Rules for this Tunnel
Select
Yes
if you want the Business Communications Manager to create Firewall rules that
allow traffic for this tunnel to pass through the Firewall.
Select
No
if you do not want Business Communications Manager to create Firewall rules for
this tunnel.
If you are using the Business Communications Manager Firewall, Nortel Networks
recommends that you select Yes for this option.
The default setting is No.
Keep-Alive Enabled
Allows for quicker detection of lost connectivity.
You can select
Yes
or
No
.
The default setting is
No
.
Note
: Leave this setting at the default value of
No
for IPSec tunnel connections to systems
other than Business Communications Manager or Contivity.
Table 234
IPSec Branch Office Tunnel settings (Continued)
Attribute
Description
Summary of Contents for BCM 3.7
Page 4: ...4 Software licensing N0008589 3 3...
Page 32: ...32 Contents N0008589 3 3 W 937 Index 939...
Page 46: ...46 Tables N0008589 3 3...
Page 64: ...64 How to get help N0008589 3 3...
Page 90: ...90 Manually activating Telnet N0008589 3 3...
Page 116: ...116 Delayed system restart N0008589 3 3...
Page 194: ...194 Configuring a data module N0008589 3 3...
Page 276: ...276 Setting line telco features N0008589 3 3...
Page 310: ...310 Using COS passwords N0008589 3 3...
Page 364: ...364 Enhanced 911 E911 configuration N0008589 3 3...
Page 380: ...380 Renumbering DNs N0008589 3 3...
Page 398: ...398 Saving wizard pages on your computer N0008589 3 3...
Page 458: ...458 Voice Mail settings N0008589 3 3...
Page 488: ...488 Setting system telco features N0008589 3 3...
Page 508: ...508 Other programming that affects public networking N0008589 3 3...
Page 522: ...522 PRI networking using Call by Call services N0008589 3 3...
Page 592: ...592 Monitoring Hunt groups N0008589 3 3...
Page 636: ...636 Configuring Double Density N0008589 3 3...
Page 640: ...640 Using the Network Update Wizard N0008589 3 3...
Page 666: ...666 Importing and Exporting DHCP data N0008589 3 3...
Page 722: ...722 Restarting the router N0008589 3 3...
Page 726: ...726 Important Web Cache considerations N0008589 3 3...
Page 748: ...748 Configuring an Interface with NAT N0008589 3 3...
Page 794: ...794 IPSec N0008589 3 3...
Page 818: ...818 Configuring the Policy Agent characteristics N0008589 3 3...
Page 832: ...832 Firewall rules for Business Communications Manager with Dialup interfaces N0008589 3 3...
Page 876: ...876 ISDN Programming N0008589 3 3...
Page 1004: ...1004 Index N0008589 3 3...