re-establish the tunnel after a set period of time.
E. Keep-Alive
The IPsec Keep-alive option ensures that the tunnel remains established at all possible times even if
no traffic flows. It does this by continuously sending ICMP Ping messages through the tunnel. If
replies to the ping messages are not received then the tunnel link is assumed to be broken and an
attempt is automatically made to re-establish the tunnel. This feature is only useful for LAN to LAN
tunnels.
With the Manual option, a specific source IP address and/or a destination IP address for the pings
can optionally be specified. It is recommended to specify a destination IP of a host which is known
to being able to reliably respond to ICMP messages.
If the Auto option is chosen and a destination IP is therefore not specified, NetDefendOS will use
the first IP address on the remote network for sending messages.
Listing IPsec Tunnels
Currently established IPsec tunnels can be listed and their usage examined through the IPsec option
in the Status menu (see Section 6.8, “IPsec Status”).
4.4.2. L2TP/PPTP Client
This option allows a tunnel to be set up where the DFL-160 acts as a L2TP or PPTP client. In this
mode, a tunnel is set up where the DFL-160 connects to an L2TP or PPTP server.
In this mode, users and hosts on the DFL-160 LAN and DMZ interfaces can connect securely to
resources at the other end of the tunnel. Unlike pure IPsec VPN where separate VPN tunnels are set
up for each user or host, only one L2TP tunnel is set up and all traffic flows through it.
The following sections appear in the web interface for setup:
A. General
B. Authentication
C. IPsec Encryption
D. Security Authentication
E. MPPE
F. Dial-on-Demand
A. General
In this section, the tunnel is named and the protocol (L2TP or PPTP is chosen).
The Remote endpoint is the IP address of the other end of the tunnel (the server's IP address). It can
be specified as a URI such as gw.domain.com but if it is then the prefix dns: must be added so the
full entry would be dns:gw.domain.com.
4.4.2. L2TP/PPTP Client
Chapter 4. The Firewall Menu
52
Содержание NetDefend SOHO DFL-160
Страница 11: ...1 3 The LED Indicators Chapter 1 Product Overview 11...
Страница 22: ...2 4 Console Port Connection Chapter 2 Initial Setup 22...
Страница 39: ...3 7 Dynamic DNS Settings Chapter 3 The System Menu 39...
Страница 76: ...4 10 Schedules Chapter 4 The Firewall Menu 76...
Страница 78: ...5 1 Ping Chapter 5 The Tools Menu 78...
Страница 93: ...6 11 DHCP Server Status Chapter 6 The Status Menu 93...
Страница 102: ...7 6 Technical Support Chapter 7 The Maintenance Menu 102...