Ipsec Advanced Settings - D-Link NetDefend DFL-210 User Manual

Network security firewall
Hide thumbs Also See for NetDefend DFL-210:
Table of Contents

Advertisement

9.4.6. IPsec Advanced Settings

Flags
Cookies
Message ID
Packet length
# payloads
Payloads:
HASH (Hash)
Payload data length : 16 bytes
9.4.6. IPsec Advanced Settings
The following NetDefendOS advanced settings are available for configuring IPsec tunnels.
IPsec Max Rules
This specifies the total number of IP rules that can be connected to IPsec tunnels. By default this is
initially approximately 4 times the licensed IPsecMaxTunnels and system memory for this is
allocated at startup. By reducing the number of rules, memory requirements can be reduced but
making this change is not recommended.
IPsec Max Rules will always be reset automatically to be approximately 4 times IPsec Max
Tunnels if the latter is changed. This linkage is broken once IPsec Max Rules is altered manually
so that subsequent changes to IPsec Max Tunnels will not cause an automatic change in IPsec Max
Rules.
Default: 4 times the license limit of IPsec Max Tunnels
IPsec Max Tunnels
Specifies the total number of tunnels allowed by NetDefendOS. This value is usually taken from the
license but in situations where it is desirable to have less than the license value it can be reduced.
System memory for the tunnels is allocated at startup and reducing this value can therefore reduce
memory requirements.
A warning log message is generated automatically when 90% of this value is reached.
Default: According to the licensed limit
IKE Send Initial Contact
Determines whether or not IKE should send the "Initial Contact" notification message. This message
is sent to each remote endpoint when a connection is opened to it and there are no previous IPsec
SA using that gateway.
Default: Enabled
IKE Send CRLs
Dictates whether or not CRLs (Certificate Revocation Lists) should be sent as part of the IKE
exchange. Should typically be set to ENABLE except where the remote peer does not understand
CRL payloads.
Note that this setting requires a restart to take effect.
Default: Enabled
: E (encryption)
: 0x6098238b67d97ea6 -> 0x5e347cb76e95a
: 0xaa71428f
: 48 bytes
: 1
360
Chapter 9. VPN

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents