Advanced Settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.40 Locally Managed Administration Guide | 154
VPN Site to Site Global
Settings Attribute
Description
Accept NAT Traversal
Indicates if industry standard NAT traversal (UDP
encapsulation) is enabled. This enables VPN tunnel
establishment even when the remote site is behind a NAT
device.
Administrative notifications
Indicates how to log an administrative event (for example,
when a certificate is about to expire)
Check validity of IPSec
reply packets
Indicated whether to check the validity of IPSec reply packets.
Cluster SA sync packets
threshold
Sync SA with other cluster members when the number of
packets reaches this threshold.
Copy DiffServ mark from
encrypted /decrypted
IPSec packet
Copy DiffServ mark from encrypted/decrypted IPSec packet.
Copy DiffServ mark to
encrypted/ decrypted
IPSec packet
Copy DiffServ mark to encrypted/decrypted IPSec packet.
DPD triggers new IKE
negotiation
DPD triggers new IKE negotiation.
Delete IKE SAs from a
dead peer
Delete IKE SAs from a dead peer.
Delete IPsec SAs on IKE
SA delete
Delete IPsec SAs on IKE SA delete.
Delete tunnel SAs when
Tunnel Test fails
When permanent VPN tunnels are enabled and a Tunnel Test
fails, delete the relevant peer's tunnel SAs.
Do not encrypt connections
originating from the local
gateway
Packets whose original source or destination IP address is the
local gateway's Internet Connection IP address will not go
through a VPN tunnel. This parameter may be useful when the
gateway behind hide NAT.
Do not encrypt local DNS
requests
When enabled, DNS requests originating from the appliance
will not be encrypted. Relevant when a configured DNS server
is in a VPN peer's encryption domain.
Enable encrypted packets
rerouting
Indicates if encrypted packets are rerouted through the best
interface according to the peer's IP address or probing. We do
not recommend to change this value to false.
Table: VPN Site to Site Global Setting Attributes