Field
Description
XAUTH Profile
Select a profile created in VPN->IPSec->XAUTH Profiles if you
wish to use this IPSec peer XAuth for authentication.
If XAuth is used together with IKE Config Mode, the transac-
tions for XAuth are carried out before the transactions for IKE
Config Mode.
Number of Admitted
Connections
Choose how many users can connect using this peer profile.
Possible values:
•
: /
(default value): Only one peer can be connected
with the data defined in this profile.
•
.3++ /
: Several peers can be connected with the
data defined in this profile. The peer entry is duplicated for
each connection request with the data defined in this profile.
The dynamic peer configuration on the gateway must not spe-
cify a peer ID or a peer IP address. Clients connecting to the
gateway, however, must have a peer ID specified in the client
peer configuration, since the ID is still used to differentiate the
tunnels created via the dynamic peer.
The resulting gateway peer would match all incoming tunnel
requests. It is, therefore, essential to put it at the end of the
IPSec peer list on the gateway. Otherwise all peers that follow
the dynamic peer in the peer list would be inactive.
Start Mode
Select how the peer is to be switched to the active state.
Possible values:
•
: -
(default value): The peer is switched to the active
state by a trigger.
•
,+20 3
: The peer is always active.
Backup Peer
If a peer has been configured for the Start Mode
,+20 3
,
you can select another, already configured peer as a backup
option. If the current peer becomes inactive, e.g. because of an
outage of the central VPN dial-in node, the backup peer can ini-
tiate a connection to a backup VPN dial-in node. If the primary
dial-in node becomes available again, the connection is seam-
lessly switched back.
bintec elmeg GmbH
14 VPN
be.IP 4isdn
245