MLR 3G 2.0
Functions
In order to
adjust the interval up to the key renegotiation
, use the entry field
"Interval for renegotiation of data channel key". This interval configures the
time in seconds, which must expire before new keys are created.
In order to adjust the
VPN ping interval
, use the entry field "Ping interval". En-
ter the interval in the amount of seconds, in which the VPN Server of the MLR
3G 2.0 sends ping packets to the remote VPN terminal. The frequent ping is
used to keep the connection open via several routers and gateways, which
may participate in the connection and would close the channel in case there
was no communication. We recommend entering a value of a few minutes,
depending on the used network and the used infrastructure.
In order to adjust the
ping restart interval
, use the entry field "Ping restart in-
terval". The ping restart interval configures the time in seconds after which
the tunnel is to be established again, if no ping from the remote terminal ar-
rived during the complete time. The value "0" prevents the tunnel to be ter-
minated, even if no ping is received any more.
In order to
configure the authentication with certificates
, select the radio but-
ton "Authentication based on certificate". It is indicated under the option here,
whether the individual certificates and keys are present (green checkmark) or
not (red cross). Present certificates can also be downloaded (blue arrow) or de-
leted again (red cross on white box). The private key can only be deleted.
Check the checkbox "Allow communication between clients" to enable a
communication between the clients as well. Define the IP address pool for the
clients in the fields "IP address pool for clients" and "Netmask of IP address
pool". In order to create a new route to a client network, enter in the section
"Create new route to a client network" the Common Name of the client into
the field "Name in certificate" as well as its network address and netmask into
the field "Net address" and "Netmask address". Optionally, enter the VPN IP
address for the tunnel end of a client into the field "VPN IP address". Click on
"OK" to take over the new route. You can delete existing routes by checking
the checkbox in the column "delete" of the respective route and clicking on
"OK".
A link of a network address with "DEFAULT" as "Common Name" may be
created as "Standard route". It is always used as route, when a client regis-
ters with a certificate, for whose "Common Name" no other link has been
entered.
51