Page 116 SonicWALL TELE3 SP Administrator’s Guide
Use Aggressive Mode
Selecting the
Use Aggressive Mode
check box forces the SonicWALL appliance to use
Aggressive Mode to establish the VPN tunnel even if the SonicWALL has a static IP address.
Aggressive Mode requires half of the main mode messages to be exchanged in Phase One of
the SA exchange.
Use Aggressive Mode
is useful when the SonicWALL is located behind
another NAT device. The check box is only available if
IKE using Pre-shared Secret
or
IKE
using certificates
(SonicWALL to SonicWALL) is selected as the
IPSec Keying Mode
.
Note
: If a WAN Failover to the modem occurs on the SP, the Security Association uses
Aggressive Mode
even if it is not configured for the SA.
Enable Keep Alive
Selecting the
Enable Keep Alive
check box allows the VPN tunnel to remain active or maintain
its current connection by listening for traffic on the network segment between the two
connections. Interruption of the signal forces the tunnel to renegotiate the connection.
Require authentication of local users
Selecting this check box requires that all outbound VPN traffic on this SA is from an
authenticated user. Unauthenticated traffic is not allowed on the VPN tunnel.
Require authentication of remote users
Enabling this feature requires that all inbound traffic on this SA is from an authenticated user.
Unauthenticated traffuc is not allowed on the VPN tunnel. Select
Remote users behind VPN
gateway
if remote users have a VPN tunnel terminating on the VPN gateway. Select
Remote
VPN clients behind VPN gateway
if remote users require authentication using XAUTH and
are accessing the SonicWALL via a VPN client.
Enable Windows Networking (NetBIOS) broadcast
Computers running Microsoft Windows
®
communicate with one another through NetBIOS
broadcast packets. Select the
Enable Windows Networking (NetBIOS) broadcast
check
box to access remote network resources by browsing the Windows
®
Network Neighborhood.