Draytek Vigor3900 User Manual page 346

Multi-wan security appliance
Hide thumbs Also See for Draytek Vigor3900:
Table of Contents

Advertisement

4.
After filling the required information for Basic, click the Advanced tab to open the
following page.
Available parameters are listed as follows:
Item
Phase 1 Key Life
Time
Phase 2 Key Life
Time
Perfect Forward
Secrecy Status
Dead Peer
Detection Status
DPD Delay
DPD Timeout
Description
The rekey-renegotiated period of the IKE Phase1 keying
channel of a connection. The acceptable range is from 5 to
480 minutes (8 hours).
The rekey-renegotiated period of the IKE Phase 2 keying
channel of a connection. The acceptable range is from 5 to
480 minutes (8 hours).
Enables the PFS function. A new Diffie-Hellman Key
Exchange is included every time an encryption and/or
authentication key are computed on PFS.
Enable – Click it to enable DPD. When there is no traffic
through the IPSec tunnel, both server and the client will send
the DPD packet to each other to ensure the IPSec tunnel
connection is active still.
Disable – Click it to disable DPD.
The keep-alive timer. A Hello message will be emitted
periodically when a tunnel is idle. Use the value 0 to disable
this function. The recommended value is 30 seconds if
enabled.
The timeout timer. The peer will be declared dead once no
acknowledge message is received after timeout value. Use
the value 0 to disable this function. The recommended value
is 120 seconds if enabled.
338
Vigor3900 Series User's Guide

Advertisement

Table of Contents
loading

Table of Contents