LevelOne GBR-4001 User Manual page 148

4-wan gigabit broadband vpn router
Table of Contents

Advertisement

Encryption and authentication algorithm (1-4): Sets the encryption and authentication
algorithm used for negotiation in the first phase. You can select four groups, each of which
the combination of different encryption algorithms and authentication algorithms and DH
groups.
Phase II
Encryption and authentication algorithm (2-4): Sets the encryption and authentication
algorithm used for negotiation the second phase, and three groups can be selected, together
with a group that has been configured in the basic parameter configuration, so there is a total
of four groups.
Survival time: Sets the survival time of IPSec SA, which is at least 600 seconds. When the
remaining time is 540 seconds, the SA will expire and the IPSec SA will be negotiated again.
Others
Anti-replay: Sets whether or not anti-replay is enabled. When enabled, the gateway will
support the anti-replay feature, to reject the received packets or copies of packets in order to
protect themselves from attacks.
DPD: Sets whether to enable DPD. After enabled, the device sends a heartbeat packet on a
regular basis to detect whether each other's network is reachable, and whether the program is
normal. If multiple heartbeat packets are lost continuously, then IPSec DPD will launch SA
negotiation again forcibly.
Heartbeat: Sets the time interval for sending heartbeat packets, whose default value is 20
seconds. After configuring this value, the gateway will send detection messages to the peer
end at an interval of unit time ("heartbeat"), to determine whether the peer end still survives.
NAT traversal: Enables or disables the feature of NAT traversal.
Port: Sets the port number of UDP encapsulation packets in NAT traversal, whose default
value is 4500.
Maintain: After NAT traversal feature is enabled, the device will send a packet to the NAT
device to maintain NAT mapping at an interval of unit time ("keep"), so that the NAT
mapping needs no change until SA in the first phase and second phase expires. Its default
value is 20 seconds.
http://www.level1.com
Chapter 12 VPN
Page 143

Advertisement

Table of Contents
loading

Table of Contents