IPsec parameters
Digi TransPort User Guide
410
Logic flow for VPN Concentrator acting as a responder to a session initiated from the
remote site
1. When a remote site needs to create an IPsec SA with the VPN Concentrator it sends an IKE
request to the VPN Concentrator.
2. The VPN Concentrator needs to be able to confirm that the remote device is authorized to
create an IPsec tunnel. The remote site supplies its ID to the host during the IKE negotiations.
The VPN Concentrator uses this ID in a search of the IPsec tunnels configured and dynamic
IPsec tunnels to see if the supplied ID matches the configured Peer ID (peerid). If a match is
found, the MYSQL database is queried to retrieve the information required to complete the
negotiation (such as pre-shared key/password). If no matching base IPsec tunnel is found, the
local user configuration is used to locate the password, and a normally configured IPsec
tunnel must also exist.
3. Once the information is retrieved from the MySQL database, IKE negotiations continue, and
the created IPsec SAs will be associated with the dynamic IPsec tunnel.
4. As long as the dynamic IPsec tunnel exists, it behaves just like a normal IPsec tunnel. such as
SAs being replaced/removed as required.
5. If errors are received from the MySQL database, or not enough fields are returned, the
dynamic IPsec tunnel is removed, and IKE negotiations in progress are terminated.
6. There are a limited number of dynamic IPsec tunnels. If the number of free dynamic IPsec
tunnel is less than 10% of the total number of dynamic IPsec tunnel, the router periodically
removes the oldest dynamic IPsec tunnel. This is done to ensure that there will always be
some free dynamic IPsec tunnel available for incoming connections from remote routers. To
view the current dynamic tunnels that exist using the WEB server, browse to
Management >
Connections > Virtual Private Networking (VPN) > IPsec
. The table indicates the base IPsec
tunnel and the
Remote Peer ID
in the status display, to help identify which remote sites are
currently connected.
Содержание TransPort
Страница 1: ...User Guide Digi TransPort ...
Страница 95: ...Regulatory and safety statements Digi TransPort User Guide 95 TransPort WR41Declaration of Conformity ...
Страница 96: ...Regulatory and safety statements Digi TransPort User Guide 96 ...
Страница 97: ...Regulatory and safety statements Digi TransPort User Guide 97 TransPort WR44 Declaration of Conformity ...
Страница 773: ...Manage files Digi TransPort User Guide 773 For example ...