85
CRADLEPOINT WIRELESS WAN
©2017 Cradlepoint. All Rights Reserved.
|
+1.855.813.3385
|
cradlepoint.com
48
User Manual
/
IBR900/IBR950
1/5/17
By default, all the algorithms (encryption, hash, and DH groups) supported by the device are checked, which
means they are allowed for any given exchange. Deselect these options to limit which algorithms will be
accepted. Be sure to check that the router (or similar device) at the other end of the tunnel has matching
algorithms.
The algorithms are listed in order by priority. You can reorder this priority list by clicking and dragging
algorithms up or down. Any selected algorithm may be used for IKE exchange, but the algorithms on the top of
the list are more likely to be used more often.
Add/Edit Tunnel – IKE Phase 2
Perfect Forward Secrecy (PFS)
: Enabling this feature will require IKE to generate a new set of keys in phase
2 rather than using the same key generated in phase 1. Additionally, with this option enabled the new keys
generated in phase 2 are exchanged in an encrypted session. Enabling this feature affords the policy greater
security.
Key Lifetime
: The lifetime of the generated keys of phase 2 of the IPsec negotiation from IKE. After the time
has expired, IKE will renegotiate a new set of phase 2 keys.
Phase 2 has the same selection of
Encryption
and
DH Groups
as phase 1, but you are restricted to only one
DH Group. Phase 2 and phase 1 selections do not have to match. For the
Hash
selection an added value of
SHA 256_128 (128-bit truncation) is avaliable. The original specification and the Cradlepoint default is 96-bit
truncation, but RFC4868 requires 128-bit. A VPN to newer Cisco or Juniper devices will typically require 128-bit.
Add/Edit Tunnel – Dead Peer Detection
Dead Peer Detection (DPD)
defines how the router
will detect when one end of the IPsec session loses
connection while a policy is in use.
Connection Idle Time
: Configure how long the router
will allow an IPsec session to be idle before beginning
to send Dead Peer Detection (DPD) packets to the
peer machine. (Default: 30 seconds. Range: 10 – 3600
seconds.)
Request Frequency
allows you to adjust the delay
between these DPD packets. (Default: 15 seconds.
Range: 2 – 30 seconds.)
Maximum Requests
: Specify how many requests to
send at the selected time interval before the tunnel
is considered dead. (Default: 5. Range: 2 – 10.)
Failback Retry Period
: If you have VPN tunnel failover/failback enabled (see below), set the time period
between each check on the primary network after failover. (Default: 10 seconds. Range: 5 – 60 seconds.)
Failover Tunnel
and
Failback Tunnel
: Use these settings to create two tunnels – one as the primary tunnel and
one as the backup tunnel. To configure tunnel failover/failback, complete the following steps:
1. Create two tunnels: one for primary and one for backup. Make sure that both tunnels have the same
Remote Network
and that both have
Dead Peer Detection
enabled.
2. Choose one to be the primary tunnel. Open the editor for this tunnel and make sure
Tunnel Enabled
is
selected. Then go to the
Dead Peer Detection
page. Under
Failover Tunnel
select the other tunnel you
have created.
3. Open the editor for the failover tunnel. Make sure
Tunnel Enabled
is
not
selected. On the
Dead Peer
Detection
page, set the
Failback Tunnel
to your primary tunnel.
Summary of Contents for LEGACY ELITE 2022
Page 2: ......
Page 22: ...22 AUTO DRAIN...
Page 149: ...149 KEYLESS ENTRY DOOR LOCK...
Page 162: ...162 Page 11 2017 Nature s Head Inc INSTALLATION Venting NATURE S HEAD COMPOSTING TOILET...
Page 204: ...204 LIFELINE AGM BATTERIES 2 2 Battery with Cut Away View...
Page 205: ...205 LIFELINE AGM BATTERIES 2 3 Terminal Types...
Page 363: ...363 XANTREX FREEDOM XC PRO INVERTER 1 N L G G L N G L N 2 1 3 4 5...
Page 364: ...364 XANTREX FREEDOM XC PRO INVERTER N L G G L N G L N 2 1 3 4 5...
Page 365: ...365 XANTREX FREEDOM XC PRO INVERTER 1 2 3...
Page 366: ...366 XANTREX FREEDOM XC PRO INVERTER 1 2 3 4 5 7 6...
Page 367: ...367 XANTREX FREEDOM XC PRO INVERTER...
Page 369: ...369 XANTREX FREEDOM XC PRO INVERTER sensor cable connector...
Page 370: ...370 XANTREX FREEDOM XC PRO INVERTER BTS Battery cable neg battery terminal BTS Battery case...
Page 371: ...371 XANTREX FREEDOM XC PRO INVERTER...
Page 372: ...372 1 11 13 12 3 5 4 10 8 9 7 6 2 XANTREX FREEDOM XC PRO INVERTER...
Page 375: ...375 XANTREX FREEDOM XC PRO INVERTER...
Page 376: ...376 XANTREX FREEDOM XC PRO INVERTER...
Page 377: ...377 XANTREX FREEDOM XC PRO INVERTER...
Page 378: ...378 XANTREX FREEDOM XC PRO INVERTER...
Page 379: ...379 XANTREX FREEDOM XC PRO INVERTER...
Page 380: ...380 XANTREX FREEDOM XC PRO INVERTER...
Page 381: ...381 XANTREX FREEDOM XC PRO INVERTER...
Page 382: ...382 XANTREX FREEDOM XC PRO INVERTER...
Page 384: ...384 XANTREX FREEDOM XC PRO INVERTER...
Page 385: ...385 XANTREX FREEDOM XC PRO INVERTER...
Page 386: ...386 XANTREX FREEDOM XC PRO INVERTER...
Page 387: ...387 XANTREX FREEDOM XC PRO INVERTER...
Page 388: ...388 XANTREX FREEDOM XC PRO INVERTER...
Page 389: ...389 XANTREX FREEDOM XC PRO INVERTER...
Page 390: ...390 XANTREX FREEDOM XC PRO INVERTER...
Page 391: ...391 XANTREX FREEDOM XC PRO INVERTER...
Page 392: ...392 XANTREX FREEDOM XC PRO INVERTER...
Page 393: ...393 267 288 9 15 290 296 305 0 9 69 336 396 406 0 27 122 125 XANTREX FREEDOM XC PRO INVERTER...
Page 394: ...394 XANTREX FREEDOM XC PRO INVERTER...
Page 395: ...395 XANTREX FREEDOM XC PRO INVERTER...
Page 396: ...396 XANTREX FREEDOM XC PRO INVERTER...
Page 397: ...397 XANTREX FREEDOM XC PRO INVERTER...
Page 408: ......
Page 409: ......