C-M-G
Series
Manual
© TDT GmbH
Chapter 5: Network Configuration
Seite 51 von 136
Command
Description
DPD Timeout
If the remote peer is still not accessible within the specified
n
seconds, the defined »DPD Action« will be executed
DPD Action
Hold:
the connection is maintained (default)
Restart:
tries to build up the connection once again
Clear:
the connection will be disconnected
5.8.3.2 Phase1(ISAKMP) Settings
Command
Description
ISAKMP Mode
Main Mode:
the IP address of the remote station is used for
authentication
Agressive Mode:
only 3 messages are exchanged after
negotiating
Due to lack of security, aggressive mode should only be
used when the remote station has no fixed IP addresses
(road warrior)
Our/Left IP
Defines the local external IP address either manually or via
dropdown menu (IP of an interface or default route)
Our/Left Next-Hop
Specifies the gateway IP via which the IPSec remote peer can be
reached
Leave this field blank if peer is accessible directly
Peer/Right IP
IPSec remote peers IP, e.g. IPSec remote peers external IP or
%any for RoadWarriors using dynamic IPs
Peer/Right Next-Hop
Specifies the gateway IP via which the IPSec remote peer can be
reached
Leave this field blank if peer is accessible directly
Authentication Method
Pre-Shared-Keys:
Authentication is based on preshared keys
Certificate:
Authentication is based on certificates
Our/Left ID
Our/Left IP:
The identification of the remote station takes place
via it’s IP address.
String:
For identification, the entered value is used
The value must be prefixed with an @
Peer/Right ID
Peer/Right IP:
The identification of the remote station takes place
via it’s IP address
String:
For identification, the entered value is used.
The value must be prefixed with an @
5.8.3.2.1 PSK-Settings
Command
Description
Pre-Shared-Key
Enter the preshared-key here
Confirm Pre-Shared-Key
Confirm the preshared key here