OnCell G3470A-LTE
Web Console Configuration
3-22
Field
Description
Factory Default
Remote ID
Enter an ID (IP/FQDN/User_FQDN) to identify and
authenticate the remote VPN endpoint.
Key Exchange (Phase1)
Operation mode
Select main mode or aggressive mode to configure the
standard negotiation parameters for IKE Phase 1 of the VPN
Tunnel.
Main
Authentication mode
Select
Pre-shared key
,
RSA Signature
or
X.509
authentication mode to for phase 1 key exchange.
The configuration fields vary depending on the authentication
mode you select. For information on configuring each
authentication mode, refer to the following sections.
Pre-shared key
Encryption algorithm
Select the DES, 3DES or AES128 algorithm for the VPN
ISAKMP phase 1 encryption mode.
DES
Hash algorithm
Select the MD5 or SHA-1 VPN key exchange phase 1 hash
mode.
MD5
DH group
Select the DH-2(1024) or DH-5(1536) VPN key exchange
phase 1 Diffie-Hellman group. As the Diffie-Hellman Group
number increases, the higher the level of encryption
implemented for PFS.
DH-2
Negotiation time
The number of allowed reconnect times when startup mode is
initiated. If the number is 0, this tunnel will always try
connecting to the remote gateway when the VPN tunnel is not
created successfully.
0
IKE life time
Enter the number of minutes for the VPN IKE SA phase 1
Lifetime. This is the period of time to pass before establishing
a new IPSec security association (SA) with the remote
endpoint.
60
Rekey expire time
Enter the number of minutes for the Start to Rekey before
IKE lifetime expired.
9
Rekey fuzz percent
The rekey expire time will change randomly to enhance the
security. Rekey fuzz percent is the maximum random change
margin of the Rekey expire time. 100% means the rekey
expire time will not change randomly.
100%
Data Exchange (phase2)
Perfect forward
secrecy
Enable or disable the Perfect Forward Secrecy. PFS is an
additional security protocol.
Disable
SA life time
Enter the number of seconds for the VPN ISAKMP phase 2
Lifetime. This is the period of time to pass before establishing
a new IPSec security association (SA) with the remote
endpoint.
480
Encryption algorithm
Select the DES, 3DES, or AES128 algorithm for the VPN
ISAKMP phase 1 encryption mode.
DES
Hash algorithm
Select the MD5 or SHA-1 VPN ISAKMP phase 1 authentication
mode.
MD5
Dead Peer Detection
DPD action
When you enable the Dead Peer Detection (DPD) feature, the
OnCell G3470A-LTE performs one of the following actions
when connection to a remote IPSec tunnel is down:
•
Hold: Keep the VPN tunnel
•
Clear: Clear the VPN tunnel
•
Restart: Re-establish the VPN tunnel on Start in Initial
mode.
Disable