14.1.2.11.3 Connection with XAuth Client
292
14.1.2.11.3-C
Phase 1
The IKE proposals configured for peers with dynamic IP will always apply.
14.1.2.11.3-D
Phase 2
Dead Peer Detection
With Dead Peer Detection (DPD) enabled, SX-GATE checks every 30 seconds whether
the peer is still alive. The check is only performed when the link is idle. If there's no
reply for 120 seconds, the connection is terminated. In case of a peer with static IP
address, SX-GATE tries to negotiate a new connection.
The peer needs to support DPD according to RFC3706 if you
want to use this feature.
In case of an expensive dialup connection (e.g. ISDN), using
DPD can become pretty expensive. Data is sent every 30
seconds, so the connection will stay online all the time.
Perfect forward secrecy
Perfect forward secrecy (PFS) for phase 2 enhances the security of a VPN connection.
An intruder who manages to access the preshared key or the private key of a VPN
will not be able to decrypt a recorded VPN session when PFS is active. Setting PFS
to "optional" is not recommended, but may be necessary for interoperability with other
IPSEC implementations.
SHA2-256 96bit draft version
The default ESP hash truncation for sha2_256 is 128 bits. Some IPsec implementations
(Linux before 2.6.33, some Cisco routers) implement the draft version which stated 96
bits.
This option enables using the draft 96 bits version to interop with those
implementations.
Another workaround is to switch from sha2_256 to sha2_384 or sha2_512.
ESP-Proposals
The phase 2 proposals determine acceptable ciphers and hash-algorithms for the
actual data transmission.
Содержание SX-GATE
Страница 1: ...State 2016 12 13 V7 0 2 0 User Guide ...
Страница 92: ...12 1 Setup 92 There s no way to restore a purchased certificate without backup ...
Страница 126: ...12 3 3 Groups 126 12 3 3 C Usage This table show in which settings the definition is used ...
Страница 476: ...15 3 Apple iPhone 476 ...