_______________________________________________________________________________________________________
_____________________________________________________________________________________________________
© Virtual Access 2017
GW7304 Series User Manual
Issue: 1.9
Page 212 of 336
Web: DPD Action
UCI: strongswan.@connection[X].dpdaction
Opt: dpdaction
Defines DPD (Dead Peer Detection) action.
None
Disables DPD.
Clear
Clear down the tunnel if peer does not respond.
Reconnect when traffic brings the tunnel up.
Hold
Clear down the tunnel and bring up as soon as
the peer is available.
Restart
Restarts DPD when no activity is detected.
Web: DPD Delay
UCI: strongswan.@connection[X].dpddelay
Opt: dpddelay
Defines the period time interval with which R_U_THERE
messages and INFORMATIONAL exchanges are sent to the
peer.
These are only sent if no other traffic is received.
30s
Timespec 1d, 2h, 25m, 10s.
Web: DPD Timeout
UCI: strongswan.@connection[X].dpdtimeout
Opt: dpdtimeout
Defines the timeout interval, after which all connections to a
peer are deleted in case of inactivity.
150s
Timespec 1d, 2h, 25m, 10s.
Web: n/a
UCI:
strongswan.@connection[X].inherit_child
Opt: inherit_child
Defines whether the existing phase two IPSEC SA is
maintained through IKE rekey for this tunnel. This is normally
set to match the behaviour on the IPSEC headend.
0
Delete the existing IPSEC SA on IKE rekey
1
Maintain the existing IPSEC SA on IKE rekey
Table 66: Information table for IPSec connections settings
24.2.5
Configure secrect settings
Each tunnel requires settings to configure how the local end point of the tunnel proves
its identity to the remote end point.
Figure 115: IPSec secrets settings
Web Field/UCI/Package Option
Description
Web: Enabled
UCI: strongswan.@secret[X].enabled
Opt: enabled
Defines whether this set of credentials is to be used or not.
0
Disabled.
1
Enabled.
Web: ID selector
UCI: strongswan.@secret[X].idtype
Opt: idtype
Defines whether IP address or userfqdn is used.
Web: ID selector
UCI: strongswan.@secret[X].localaddress
Opt: localaddress
Defines the local address this secret applies to.