Digi Connect EZ Mini User Manual page 132

Firmware version 22.2
Hide thumbs Also See for Connect EZ Mini:
Table of Contents

Advertisement

Virtual Private Networks (VPN)
i. For Port, type the port matching criteria.
Allowed values are a port number, a range of port numbers, or any.
21. Click to expand IKE.
a. For IKE version, select either IKEv1 or IKEv2. This setting must match the peer's IKE
version.
b. Initiate connection instructs the device to initiate the key exchange, rather than waiting
for an incoming request. This must be disabled if Remote endpoint >
any.
c. For Mode, select either Main mode or Aggressive mode.
d. For IKE fragmentation, select one of the following:
n
n
n
n
The default is Always.
e. For Enable padding, click to disable the padding of IKE packets. This should normally not
be disabled except for compatibility purposes.
f. For Phase 1 lifetime, enter the amount of time that the IKE security association expires
after a successful negotiation and must be re-authenticated.
Allowed values are any number of weeks, days, hours, minutes, or seconds, and take the
format number{w|d|h|m|s}.
For example, to set Phase 1 lifetime to ten minutes, enter 10m or 600s.
g. For Phase 2 lifetime, enter the amount of time that the IKE security association expires
after a successful negotiation and must be rekeyed.
Allowed values are any number of weeks, days, hours, minutes, or seconds, and take the
format number{w|d|h|m|s}.
For example, to set Phase 2 lifetime to ten minutes, enter 10m or 600s.
Digi Connect EZ Mini User Guide
If supported by the peer: Send oversized IKE messages in fragments, if the peer
supports receiving them.
Always: Always send IKEv1 messages in fragments. For IKEv2, this option is
equivalent to If supported by the peer.
Never: Do not send oversized IKE messages in fragments.
Accept: Do not send oversized IKE messages in fragments, but announce support
for fragmentation to the peer.
IPsec
Hostname
is set to
132

Advertisement

Table of Contents
loading

Table of Contents