C-M-G
Series
Manual
© TDT GmbH
Chapter 5: Network Configuration
Seite 49 von 136
5.8.1.1 Configure IPSec-Interface-Mappings
The individual IPSec routes are assigned to the interface here.
Command
Description
Use ipsec0 as defaultroute
Use default route interface as ipsec0
Bind ipsec
X
to
The indivudual IPSec interfaces will be routed via the mapped
interfaces
5.8.1.1 Configure Miscellaneous Settings
This area is for miscellaneous IPSec settings.
Kommando
Beschreibung
Enable NAT-Traversal
enables/disables NAT-T (default: Yes)
Deny RSA-Connections on
missing or expired CRL
When this option is enabled, all connections with an expired or
missing CRL (X.509 Certificate Revocation List) will be denied
CRL-Check Interval
Interval, specified in seconds, after which IPSec will verify loaded
X.509 CRL's for expiration
Wait for negotiation attempt
before starting next
Yes:
Every connection build-up must be completed before the
next connection can be built-up
No:
IPSec ignores the connection status during connection build-
up (default)
Set MTU of ipsec-Interfaces
to
Defines the MTU size of IPsec interfaces (only necessary in
particular cases)
Virtual Private Subnets (for
NAT-T)
Defines the allowed subnets in the following scheme, multiple
values are comma separated
IPv4:
%v4:1.2.3.4/mm
IPv6:
%v6:aaaa::bbbb:cccc:dddd:eeee/mm
(default: %v4:10.0.0.0/8,%v4:192.168.0.0/16,%v4:172.16.0.0/12)
Script to run before IPSec
gets started
A script that will be executed before IPSec gets started
Script to run after IPSec was
started
A script that will be executed after IPSec was started
5.8.2 Debug & Log
The IPSec events, which protocol the IPSec services are defined in the Debug & Log menu.
Command
Description
Core dump settings for
programs started by ipsec
No core dumps:
a core memory dump will not be created during
IPSec start
To directory:
a core memory dump will be created during IPSec
start and written in the following directory
KLIPS Debug
K
erne
LIP
sec
S
upport Debug permits setup of the debug depth in
the core-implemented part of IPSec.
All:
All functions of the IPSec core sector will be logged
None:
No functions of the IPSec core sector will be logged