SIP-2
75/145
USER GUIDE - Rev. 3 (January 2018)
•
Transform Set.
This selects the set of previously-defined parameters that will be
used for establishing the
IPSec Security association.
•
Enable.
This enables the configured tunnel. It allows the user to have configured
operative or non-operative tunnels, as wished.
•
Valid Interface.
This indicates the valid device identifier upon which the tunnel can
be established. It operates like an additional filter. The value
any
is accepted.
IKE General Data:
•
Own ID Type.
This indicates the type of identification to be used by the equipment.
The options are
none
,
address
entailing the use of the IP address,
fqdn
, which
involves using a domain (e.g. foo.domain.com), or
user_fqdn
, entailing the use of
an e-mail address (e.g. [email protected]).
•
Own ID Value.
The own identity value in the case of selecting an option other than
none
in the preceding parameter.
•
NAT-T.
It enables the use of the option
NAT-T
, allowing the IPSec protocol to
function correctly when NAT services are crossed. The options are
off
, when the
user does not want it to be enabled or it will not be accepted if proposed by the
remote end, which is also the default value.
On
means that the option will be used
when detecting the presence of NAT services between both ends, and
force
entails its use regardless of whether or not the presence of NAT services is
detected.
•
DPD Delay.
This parameter sets the time between Hello messages transmitted for
the tunnel supervision function. The valid range of values is 0 to 1200, and the
units are seconds. 0 means the supervision is not executed.
•
DPD Retry.
This establishes the waiting time for a response to a Hello message
transmitted, in seconds. If no response is received from the remote end within this
time, the equipment considers that a supervision failure has occurred
.
•
DPD Maxfail.
The value of this parameter is the maximum admitted number of
failures to respond to a Hello message. If this maximum number is reached it is
considered that the tunnel is not available and an attempt will be made to restore it.
•
DPD Reverse Initiator-Responder.
This option allows the use of the DPD
supervision service with tunnels ended by Cisco equipment that execute a non-
standard variation.