Digi Connect IT Mini User Manual page 187

Hide thumbs Also See for Connect IT Mini:
Table of Contents

Advertisement

Virtual Private Networks (VPN)
IKE configuration items
n
The IKE version, either IKEv1 or IKEv2.
l
Whether to initiate a key exchange or wait for an incoming request.
l
The IKE mode, either main aggressive.
l
The IKE authentication protocol to use for the IPsec tunnel negotiation during phase 1 and
l
phase 2.
The IKE encryption protocol to use for the IPsec tunnel negotiation during phase 1 and
l
phase 2.
The IKE Diffie-Hellman group to use for the IPsec tunnel negotiation during phase 1 and
l
phase 2.
Enable dead peer detection and configure the delay and timeout.
n
Destination networks that require source NAT.
n
Active recovery configuration. See
n
about IPsec active recovery.
Additional configuration items
The following additional configuration settings are not typically configured to get an IPsec tunnel
working, but can be configured as needed:
Determine whether the device should use UDP encapsulation even when it does not detect
n
that NAT is being used.
If using IPsec failover, identify the primary tunnel during configuration of the backup tunnel.
n
The Network Address Translation (NAT) keep alive time.
n
The protocol, either Encapsulating Security Payload (ESP) or Authentication Header (AH).
n
The management priority for the IPsec tunnel interface. The active interface with the highest
n
management priority will have its address reported as the preferred contact address for
central management and direct device access.
Enable XAUTH client authentication, and the username and password to be used to
n
authenticate with the remote peer.
Enable Mode-configuration (MODECFG) to receive configuration information, such as the
n
private IP address, from the remote peer.
Disable the padding of IKE packets. This should normally not be done except for compatibility
n
purposes.
Destination networks that require source NAT.
n
Tunnel and key renegotiating
n
The lifetime of the IPsec tunnel before it is renegotiated.
l
The amount of time before the IKE phase 1 lifetime expires.
l
The amount of time before the IKE phase 2 lifetime expires
l
The lifetime margin, a randomizing amount of time before the IPsec tunnel is renegotiated.
l
Digi Connect IT® Mini User Guide
Configure SureLink active recovery for IPsec
IPsec
for information
187

Advertisement

Table of Contents
loading

Table of Contents