Identification" Tab; Approved Certificate Authorities - Stormshield SN series Configuration Manual

Hide thumbs Also See for SN series:
Table of Contents

Advertisement

DPD

"Identification" tab

Approved certificate authorities

This table will allow you to list the authorities in order to identify your peers within the IPSec VPN
module.
Add
When you click on this button, a window will open showing the CAs and sub-CAs that you have
created earlier.
Select the authorities that will enable you to check the identities of your peers, by clicking on
Select. The CA or sub-CA selected will be added to the table.
Delete
Select the CA to be removed from the list and click on Delete.
CA
Below this field, the added and approved certificate authorities will be displayed.
Page 175/448
This field allows configuring the DPD (Dead Peer Detection) VPN feature. This would
allow checking whether a peer is still operational.
When DPD is enabled on a peer, requests (R U there) are sent to test the availability
of the other peer , who will need to acknowledge the requests in order to validate his
availability (R U there ACK).
These exchanges are secured via ISAKMP (Internet Security Association and Key
Management Protocol) SAs.
If it is detected that a peer is no longer responding, the negotiated SAs will be
destroyed.
Warning
This feature provides stability to the VPN service on Stormshield Network
Firewalls on the condition that the DPD has been correctly configured.
Four choices are available for configuring DPD:
Inactive: DPD requests from the peer are ignored.
Passive: DPD requests sent by the peer get a response from the firewall. However, the
firewall does not send any.
Low: the frequency of DPD packets being sent is low and the number of failures
tolerated is higher (delay 600, retry 10, maxfail 5).
High: the frequency of DPD packets being sent is high and the number of failures
relatively low (delay 30, retry 5, maxfail 3).
The value delay defines the period after a response is received before the next
request is sent.
The value retry defines the time to wait for a response before sending the request
again.
The value maxfail is the number of requests sent without receiving responses before
the peer is considered absent.
SNS - USER CONFIGURATION MANUAL V.3
sns-en-user_configuration_manual-v3 - Copyright © Stormshield 2016
IPSEC VPN

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents