When there is outbound traffic but no inbound traffic, the SA times out automatically after two
minutes. A tunnel with no outbound or inbound traffic is "idle" and does not timeout until the SA
lifetime period expires. See section 16.6 on keep alive to have the Prestige renegotiate an IPSec SA
when the SA lifetime expires, even if there is no traffic.
The following table describes the fields in this screen.
LABEL
No
This is the security association index number.
Name
This field displays the identification name for this VPN policy.
Encapsulation
This field displays Tunnel or Transport mode.
IPSec Algorithm
This field displays the security protocols used for an SA.
Both AH and ESP increase Prestige processing requirements and communications latency
(delay).
VPN Screens
Figure 16-9 VPN: SA Monitor
Table 16-10 VPN: SA Monitor
DESCRIPTION
Prestige 662HW Series User's Guide
16-21