Primary server port
determines the SSH-VPN TCP port on the primary server. The
default is 22.
Primary server GW
is used if another gateway than the default route is needed to
reach the gateway.
Max duration (0=unlimited)
determines the maximum duration of the VPN
connection. On the primary server, this should be set to zero. With the backup
server, the primary server is tried again after this time-out.
Connection start timeout (sec)
determines the time to wait until the connection is
established.
Connection retry interval (sec)
determines the time interval after which the
connection is retried.
Connection retry mode
increases incrementally the retry interval on each
connection attempt. Constant delay always uses the same delay.
Hello interval (sec)
determines the Hello packet interval for the VPN. This can be
used as a keep-alive message on very critical links.
Hello failure limit
determines the number of Hello packets that can be lost before
restarting the connection.
Backup server (optional)
Use backup SSH-VPN?
When set to “Yes”, the device tries to establish a VPN
connection to back up the gateway, if the primary gateway cannot be reached.
Primary failure limit
determines the number of times the primary must not be
reached before changing to the secondary. The other parameters are same as in the
primary server. The duration of the connection can be set, for example, to 3600
seconds, so after one hour's connection time to the backup server, the system tries
to reach the secondary gateway.
Routing
Routing mode
has three modes.
•
Tunnel the following network. This adds the “Remote network IP” to be
reached via the SSH-VPN. The parameters
Remote network IP
and
Remote
network mask
must be set.
•
Default route. The VPN interface is used as the default route.
•
None. No routing is added when the VPN is established. The VPN peer IPs
can be used for communications.
Remote network IP
determines the remote network IP behind the VPN on the
gateway side that the device needs to reach.
Remote network mask
determines the network mask for the remote network IP.
1MRS757105 B
Section 5
RER601/603 Configurator
RER601/603
29
Technical Manual