Chapter 8 Configuring IPSec mobility and persistent mode
155
Nortel VPN Router Configuration — Basic Features
Persistent tunneling
A persistent VPN connection provides the ability to maintain a VPN connection
without user intervention for a designated period of time. After successfully
establishing a tunnel session to the Nortel VPN Router, the Nortel VPN Client
makes every attempt to maintain a viable VPN connection.
Persistence makes use of the automatic failover capability already available with
the Nortel VPN Router and extends this to allow the new tunnel to be established
without having to re-enter user credentials. A configuration option on the Nortel
VPN Router allows you to specify that VPN clients will cache their VPN
credentials for a specified period of time. If failover is initiated during this time
(persistent time), the client automatically sends the credentials the user submitted
to set up the first tunnel session.
The Nortel VPN Client accepts a list of failover hosts configured on the Nortel
VPN Router and tries to connect to those servers if the connection with the
primary server is lost. As each failover server destination is attempted, you are
prompted, allowing you the option to cancel the operation. If the user doesn’t
intervene, the connection attempt continues. With persistence enabled, after going
through the list of failover servers, the client tries the primary and then the initially
supplied failover servers again in the loop until the client connects or until the
persistency timer expires, whichever comes first.
Session persistence time
The purpose of this timer is to allow the persistent tunnel only for certain amount
of time after the initial login. This prevents security threats such as a stolen laptop
accessing the network due to persistence for longer durations. By setting this
timer to 24 hours, users can use the VPN connectivity for work without requiring
to login more than once.
Note:
If an authentication method with a challenge ,a one time password
(such as secure ID*), or Nortel VPN Router one time password is
enabled, it will not work for persistence. However, user name/
password-based and certificate-based authentication will work.
Summary of Contents for Contivity 1050
Page 10: ...10 Contents NN46110 500 ...
Page 14: ...14 Tables NN46110 500 ...
Page 22: ...22 Preface NN46110 500 ...
Page 58: ...58 Chapter 2 Getting started NN46110 500 ...
Page 74: ...74 Chapter 3 Setting up the Nortel VPN Router 1010 1050 and 1100 NN46110 500 ...
Page 90: ...90 Chapter 4 Configuring user tunnels NN46110 500 ...
Page 118: ...118 Chapter 5 Configuring the system NN46110 500 ...
Page 162: ...162 Chapter 8 Configuring IPSec mobility and persistent mode NN46110 500 ...
Page 164: ...164 Branch office quick start template NN46110 500 ...
Page 178: ...178 Index NN46110 500 W Web browser interface 50 Web interface options 53 Welcome display 56 ...