Configuring Keepalive Timers; Setting The Nat Keepalive Timer; Configuring A Dpd - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

Configuring Keepalive
Timers
Setting the NAT
Keepalive Timer

Configuring a DPD

its identity to the peer, whereas the peer uses the IP address configured with
the remote-name ip-address command to authenticate the initiator.
Therefore, the local IP address for a device must be identical to the remote IP
address configured on its peer.
IKE maintains the link state of an ISAKMP SA by Keepalive packets. Generally, if
the keepalive timeout is configured on the peer, the keepalive packet transmission
interval must be configured on the local end. If the peer receives no keepalive
packet during the timeout interval, the ISAKMP SA will be tagged with the
TIMEOUT tag (if it does not have the tag), or deleted along with the IPSec SAs it
negotiated (when it has the tag already).
Follow these steps to configure keepalive timers:
To do...
Enter system view
Set the ISAKMP SA keepalive
interval
Set the ISAKMP SA keepalive
timeout
n
The keepalive timeout configured at the local end must be longer than the
keepalive interval configured at the remote end. Since it seldom occurs that more
than three consecutive packets are lost on a network, the keepalive timeout can
be configured to be three times of the keepalive interval.
NAT mapping on a NAT gateway may get aged. If no packet traverses an IPSec
tunnel in a certain period of time, the NAT mapping will be deleted, disabling the
tunnel beyond the NAT gateway from transferring data. To prevent NAT mapping
from being aged, an ISAKMP SA sends to its peer NAT Keepalive packets at a
certain interval to keep the NAT session alive.
Follow these steps to set the NAT keepalive timer:
To do...
Enter system view
Set the NAT keepalive interval ike sa nat-keepalive-timer
Dead peer detection (DPD) is used to detect the state of IPSec peers. With the DPD
function enabled, if an end receives no IPSec protected packets from its peer in the
DPD query triggering interval, it sends a request to the peer to detect whether the
IKE peer exists.

Configuring Keepalive Timers

Use the command...
system-view
ike sa keepalive-timer
interval seconds
ike sa keepalive-timer
timeout seconds
Use the command...
system-view
seconds
1907
Remarks
-
Required
No keepalive packet is sent by
default.
Required
No keepalive packet is sent by
default.
Remarks
-
Required
No NAT keepalive packet is
sent by default.

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents