freeGuard 100 CLI User Manual
259
on the remote peer or client. • When the VPN peer or client
has a dynamic IP address and uses aggressive mode,
select up to three DH groups on the freeGuard 100 and one
DH group on the remote peer or dialup client. The setting on
the remote peer or client must be identical to one of the
selections on the freeGuard 100. • If the VPN peer or client
employs main mode, you can select multiple DH groups. At
least one of the settings on the remote peer or client must
be identical to the selections on the freeGuard 100.
Dpd {disable | enable}
Enable or disable DPD (Dead Peer Detection). DPD detects
the status of the connection between VPN peers. Enabling
DPD facilitates cleaning up dead connections and
establishing new VPN tunnels. DPD is not supported by all
vendors and is not used unless DPD is supported and
enabled by both VPN peers.
Disable
dpd-idlecleanup
<seconds_integer>
The DPD long idle setting when dpd is set to enable. Set the
time, in seconds, that a link must remain unused before the
local VPN peer pro-actively probes its state. After this period
of time expires, the local peer will send a DPD probe to
determine the status of the link even ifthere is no traffic
between the local peer and the remote peer. The dpd-idle
clean up range is 100 to 28 800 and must be greater than
the dpd-idle worry setting.
300 seconds
dpd-idleworry
<seconds_integer>
The DPD short idle setting when dpd is set to enable. Set
the time, in seconds, that a link must remain unused before
the local VPN peer considers it to be idle. After this period of
time expires, whenever the local peer sends traffic to the
remote VPN peer it will also send a DPD probe to determine
the status of the link. The dpd-idle worry range is 1 to 300.
To control the length of time that the freeGuard 100 takes to
detect a dead peer with DPD probes, use the dpd-retry
count and dpd retry interval keywords.
10 seconds
dpd-retrycount
<retry_integer>
The DPD retry count when dpd is set to enable. Set the
number of times that the local VPN peer sends a DPD probe
before it considers the link to be dead and tears down the
security association (SA). The dpd retry count range is 0 to
10. To avoid false negatives due to congestion or other
transient failures, set the retry count to a sufficiently high
value for your network.
3
dpd-retryinterval
<seconds_integer>
The DPD retry interval when dpd is set to enable. Set the
time, in seconds, that the local VPN peer waits between
sending DPD probes. The dpd-retry interval range is 1 to 60.
5 seconds
keepalive
<seconds_integer>
Set the NAT traversal keep alive frequency. This number
specifies, in seconds, how frequently empty UDP packets
are sent through the NAT device to make sure that the NAT
mapping does not change until P1 and P2 security
associations expire. The keep alive frequency can be from 0
to 900 seconds.
5 seconds
Содержание freeGuard 100
Страница 1: ...freeGuard 100 UTM Firewall CLI USER S MANUAL P N F0025000 Rev 1 1...
Страница 3: ......
Страница 7: ......
Страница 87: ...80 The config ips anomaly command has 1 subcommand config limit...
Страница 183: ...176...
Страница 309: ...302 100 from a TFTP server with the address 192 168 21 54 set vpn certificates local import branch_cert 192 168 21 54...