C-M-G
Series
Manual
© TDT GmbH
Chapter 5: Network Configuration
Seite 53 von 136
5.8.3.2.5 IKE Settings
Command
Description
IKE algorithms
Encryption Authentication MODP-Group
IKE Lifetime
This value defines the lifetime of the ISAKMP SA (default: 1h,
maximum 24h)
5.8.3.2.6 Rekeying Settings
Command
Description
Perform Rekeying
Defines if rekeying takes places for the session key
Rekey Margin
This value defines the time period when negotiations for a new
session key commence, prior to the expiry of the key lifetime. The
default value is 9 minutes (
9m
).
Rekey Fuzz
This percent value defines the amount the rekeying margin value
deviates from the set value. For this the rekeying intervals are
randomly selected. Values between 0% and 100%. (default:
100%)
Keying Trials
Defines how many tries or retries are permitted when building-up
a connection. The value
%forever
or
0
means »never give up«
(default: %forever)
5.8.3.3 Phase2 Settings
Kommando
Beschreibung
Local Subnet
Defines the local private subnet behind the VPN-gateway.
Syntax: IP address / subnet range (e.g.:
192.168.0.0/32
)
Local Source IP
Local IP address representing the tunnel endpoint on remote side.
This value is needed for subnet-subnet connections to route
packets through the tunnel.
Remote Subnet
Defines the remote subnet behind the remote VPN gateway
Syntax: IP address / subnet range (e.g.:
192.168.1.0/32
)
Remote Source IP
Remote source IP address representing the remote tunnel
endpoint
Die remote IP Adresse, die das Ende des Tunnels darstellt.
IP-Routing-Metric
Specifies the routing metric for the ipsec interface
Local Protocol/Port
Defines the allowed protocol and port for the tunnel
Remote Protocol/Port
Defines the allowed protocol and port for the tunnel
Use IP Compression
Defines if IP compression (RFC 2393) for better throughput on
small WAN bandwith (default: No)
Send Initial-Contact-
Notification
During a new connection attempt the router transmit an additional
payload message to the remote side that all IPsec-SA
connections related to the current source IP address are obsolete
(default: No)