Robustel GoRugged R3000 User Guide
RT_R3000_UG_v01.01
Confidential
15.03.2013
41 /
82
PFS Group
Select from “PFS_NULL”, “MODP768_1”, “MODP1024_2” and
“MODP1536_5”.
PFS_NULL: Disable PFS Group
MODP768_1: Uses the 768-bit Diffie-Hellman group.
MODP1024_2: Uses the 1024-bit Diffie-Hellman group.
MODP1536_5: Uses the 1536-bit Diffie-Hellman group.
PFS_NULL
Life Time @ SA
Parameter
Set the IPsec SA lifetime.
Note: When negotiating to set up IPsec SAs, IKE uses the smaller one between
the lifetime set locally and the lifetime proposed by the peer.
28800
DPD Time
Interval
Set the interval after which DPD is triggered if no IPsec protected packets is
received from the peer.
DPD: Dead peer detection. DPD irregularly detects dead IKE peers. When the
local end sends an IPsec packet, DPD checks the time the last IPsec packet
was received from the peer. If the time exceeds the DPD interval, it sends a
DPD hello to the peer. If the local end receives no DPD acknowledgement
within the DPD packet retransmission interval, it retransmits the DPD hello. If
the local end still receives no DPD acknowledgement after having made the
maximum number of retransmission attempts, it considers the peer already
dead, and clears the IKE SA and the IPsec SAs based on the IKE SA.
180
DPD Timeout
Set the timeout of DPD packets.
60
VPN Over IPsec
Type
Select from “None”, “L2TP” and “GRE”.
L2TP Over IPsec: Encrypt theL2TP tunnels using IPsec.
GRE Over IPsec: Encrypt the GRE tunnels using IPsec.
None
Enable Compress
Tick to enable compressing the inner headers of IP packets.
Disable
Please Add IPsec
Tunnel
Click Add to add IPsec Tunnel
Null