14.1.2.11.1 Connection with Server
281
If no proposals have been entered here, all combinations
SX-GATE supports will be accepted. If SX-GATE initiates
the connection, it will propose AES-256, AES-128 and 3DES
together with SHA1 and MD5 plus Diffie-Hellman groups 14, 5
and 2.
14.1.2.11.1-D
Phase 2
Rekeying of VPN connection every
Select the period of time after which a new session key for the VPN data packets has
to be negotiated.
Dead Peer Detection
With Dead Peer Detection (DPD) enabled, SX-GATE checks every 30 seconds whether
the peer is still alive. The check is only performed when the link is idle. If there's no
reply for 120 seconds, the connection is terminated. In case of a peer with static IP
address, SX-GATE tries to negotiate a new connection.
The peer needs to support DPD according to RFC3706 if you
want to use this feature.
In case of an expensive dialup connection (e.g. ISDN), using
DPD can become pretty expensive. Data is sent every 30
seconds, so the connection will stay online all the time.
IPComp compression
If enabled the data to transmit is compressed before encryption.
An inbound connection will be refused if the peer uses a different
compression setting.
Perfect forward secrecy
Perfect forward secrecy (PFS) for phase 2 enhances the security of a VPN connection.
An intruder who manages to access the preshared key or the private key of a VPN
will not be able to decrypt a recorded VPN session when PFS is active. Disabling
Содержание SX-GATE
Страница 1: ...State 2016 12 13 V7 0 2 0 User Guide ...
Страница 92: ...12 1 Setup 92 There s no way to restore a purchased certificate without backup ...
Страница 126: ...12 3 3 Groups 126 12 3 3 C Usage This table show in which settings the definition is used ...
Страница 476: ...15 3 Apple iPhone 476 ...