Restart on link change:
If checked, the tunnel is restarted whenever any link changes the
status.
Note
Running NAT-Traversal makes IKE using UDP port 4500 rather than 500 which has to be
taken into account when setting up firewall rules.
Configuration
General
Remote peer address:
The IPsec peer/responder/server IP address or host name
Administrative status:
Enable or disable Dead Peer Detection. DPD will detect any broken
IPSec connection, in particular the ISAKMP tunnel, and refresh the
corresponding SAs (Security Associations) and SPIs (Security Payload
Identifiers) for a faster tunnel re-establishment.
Detection cycle:
Set the delay (in seconds) between Dead Peer Detection (RFC 3706)
keepalives (R_U_THERE, R_U_THERE_ACK) that are sent for this
connection (default 30 seconds)
Failure threshold:
The number of unanswered DPD R_U_THERE requests until the IPsec
peer is considered dead (the router will then try to re-establish a dead
connection automatically)
Action:
The action when a DPD enabled peer is declared dead. Hold (default)
means the eroute is put into the hold status, while clear means the
eroute and SA will both be cleared. Restart means that the SA will be
immediately renegotiated.
95
© RACOM s.r.o. – M!DGE2 GPRS/UMTS/HSPA+/LTE router
Web Configuration
Summary of Contents for M!DGE2
Page 2: ......
Page 188: ...188 ...