Digi IX40 User Manual page 380

Table of Contents

Advertisement

Virtual Private Networks (VPN)
g. Set the port matching criteria for the remote traffic selector:
(config vpn ipsec tunnel ipsec_example policy 0)> remote port value
(config vpn ipsec tunnel ipsec_example policy 0)>
where value is the port number, a range of port numbers, or the keyword any.
h. Set the protocol matching criteria for the remote traffic selector:
(config vpn ipsec tunnel ipsec_example policy 0)> remote protocol value
(config vpn ipsec tunnel ipsec_example policy 0)>
where value is one of:
n
n
n
n
n
19. (Optional) You can also configure various IPsec related time out, keep alive, and related values:
a. Change to the root of the configuration schema:
(config vpn ipsec tunnel ipsec_example policy 0)> ...
(config)>
b. Use the ?to determine available options:
(config)> vpn ipsec advanced ?
Advanced: Advanced configuration that applies to all IPsec tunnels.
Parameters
------------------------------------------------------------------------------
debug
ike_fragment_size
ike_retransmit_tries
keep_alive
Additional Configuration
-------------------------------------------------------------------------------
connection_retry_timeout Connection retry timeout
connection_try_interval Connection try interval
ike_timeout
(config)>
Generally, the default settings for these should be sufficient.
IX40 User Guide
any: Matches any protocol.
tcp: Matches TCP protocol only.
udp: Matches UDP protocol only.
icmp: Matches ICMP requests only.
other: Matches an unlisted protocol.
If other is used, set the number of the protocol:
(config vpn ipsec tunnel ipsec_example policy 0)> remote protocol_other int
(config vpn ipsec tunnel ipsec_example policy 0)>
Allowed values are an integer between 1 and 255.
Current Value
none
Debug level
1280
5
IKE retransmit tries
40s
NAT keep alive time
IKE timeout
Maximum IKE fragment size
IPsec
380

Advertisement

Table of Contents
loading

Table of Contents