Chapter 8 Configuring IPSec mobility and persistent mode
153
Nortel VPN Router Configuration — Basic Features
When operating in IPSec mobility mode with split tunneling enabled, the Nortel
VPN Client does not consider the routing table to be maliciously altered and will
not bring down the tunnel in the following cases:
•
IP address change for any adapter
•
Adapter has been removed
•
Adapter is plugged in and connects
Initial contact payload (ICP)
If the Nortel VPN Client fails to notify the Nortel VPN Router of the logoff or
tunnel termination due to network problems (such as, the interface went down
before sending logoff sequence), the client's session could still be in the session
table for a period of time specified by the Idle Timeout. If the client tries to
reconnect and the previous session has not expired yet, the client would not be
able to log in, as only one active session is allowed per user by default.
The Initial Contact Payload feature could be used in this situation to clear up old
sessions. This feature allows the server to terminate an old session if a new session
has the same user ID as the old one.
Beginning with version 5.01, the Nortel VPN Client always sends the Initial
Contact Payload; such behavior could be accepted or rejected by the Nortel VPN
Router based on the VPN Router configuration. The “Accept ISAKMP Initial
Contact Payload” parameter configured per group specifies Nortel VPN Router
action towards received initial contact payload.
Note:
With IPC the server cannot identify the session to terminate if a
user is logged in multiple times. Nortel recommends using IPC when the
max login is set to 1.
Summary of Contents for Contivity 1050
Page 10: ...10 Contents NN46110 500 ...
Page 14: ...14 Tables NN46110 500 ...
Page 22: ...22 Preface NN46110 500 ...
Page 58: ...58 Chapter 2 Getting started NN46110 500 ...
Page 74: ...74 Chapter 3 Setting up the Nortel VPN Router 1010 1050 and 1100 NN46110 500 ...
Page 90: ...90 Chapter 4 Configuring user tunnels NN46110 500 ...
Page 118: ...118 Chapter 5 Configuring the system NN46110 500 ...
Page 162: ...162 Chapter 8 Configuring IPSec mobility and persistent mode NN46110 500 ...
Page 164: ...164 Branch office quick start template NN46110 500 ...
Page 178: ...178 Index NN46110 500 W Web browser interface 50 Web interface options 53 Welcome display 56 ...