14.1.2.11.2 Connection with Client
287
You have to import the public key of the client itself and not the
public key of the issuing Certification Authority (CA).
14.1.2.11.2-C
Phase 1
Rekeying of IKE communication every
Select the period of time after which the Internet key exchange servers have to
negotiate a new session key for encrypting the messages passed between them.
14.1.2.11.2-D
Phase 2
Rekeying of VPN connection every
Select the period of time after which a new session key for the VPN data packets has
to be negotiated.
Dead Peer Detection
With Dead Peer Detection (DPD) enabled, SX-GATE checks every 30 seconds whether
the peer is still alive. The check is only performed when the link is idle. If there's no
reply for 120 seconds, the connection is terminated. In case of a peer with static IP
address, SX-GATE tries to negotiate a new connection.
The peer needs to support DPD according to RFC3706 if you
want to use this feature.
In case of an expensive dialup connection (e.g. ISDN), using
DPD can become pretty expensive. Data is sent every 30
seconds, so the connection will stay online all the time.
Perfect forward secrecy
Perfect forward secrecy (PFS) for phase 2 enhances the security of a VPN connection.
An intruder who manages to access the preshared key or the private key of a VPN
will not be able to decrypt a recorded VPN session when PFS is active. Setting PFS
to "optional" is not recommended, but may be necessary for interoperability with other
IPSEC implementations.