Avaya G430 Manual page 491

Administering branch gateway
Hide thumbs Also See for G430:
Table of Contents

Advertisement

5. If you wish to work in IKE aggressive mode, use the initiate mode
6. If you want to listen in to communication from a remote peer that has a dynamic IP
7. Specify the branch device (Branch Gateway) by its address or by the FQDN name
8. Enable Dead Peer Detection (DPD) keepalives that check whether the remote peer
9. Bind peer status to an object tracker that can monitor hosts inside the remote peer's
Administering Avaya G430 Branch Gateway
aggressive command.
Note:
Aggressive mode is one of the prerequisites for working with dynamic local peer
IP addresses. For more information about working with dynamic local peer IP
addresses, see
Dynamic local peer IP
For example:
Gxxx-001(config-peer:149.49.70.1)# initiate mode aggressive
Done!
address, use the initiate mode none command.
In this mode, the device can only accept inbound IKE Aggressive Mode connections
from the peer, and is not able to initiate IKE phase-1 (Main Mode or Aggressive
Mode) to the peer, nor is the peer able to participate as part of a peer-group. In
addition, specifying the continuous-channel command when configuring the
crypto ISAKMP peer information has no effect in this mode. For more information
on continuous-channel, see
that identifies the Branch Gateway in the remote peer, using the self-
identity command.
Note:
Specifying self-identity as a name is one of the prerequisites for working with
dynamic local peer IP addresses. For more information about working with
dynamic local peer IP addresses, see
For example:
Gxxx-001(config-peer:149.49.70.1)# self-identity address
Done!
Gxxx-001(config-peer:149.49.70.1)# self-identity fqdn vpn.avaya.com
Done!
is up using the keepalive command, followed by the number of seconds between
DPD keepalive probes, and the number of seconds between retries if keepalive
fails.
The following example sets DPD keepalive to send probes every 10 seconds, and
to send retries every two seconds if DPD keepalive fails.
Gxxx-001(config-peer:149.49.70.1)# keepalive 10 retry 2
Done!
protected network.
on page 509.
Continuous channel
on page 512.
Dynamic local peer IP
IPSec VPN
on page 509.
October 2013
491

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents