6-8 Administrator's Handbook
Negotiation...
SA Use Policy...
Allow Dangling Phase 2 SAs:
Phase 1 SA Lifetime (seconds):
Phase 1 SA Lifetime (Kbytes):
Send Initial Contact Message:
Include Vendor ID Payload:
Independent Phase 2 Re-keys:
Strict Port Policy:
Invalid SPI recovery:
Traffic based Dead Peer Detection: Yes
DPD Keepalive Idle Time (seconds): 20
Return/Enter to select <among/between> ...
Normally it is not necessary to change the settings of the items on the Advanced IKE Phase 1 Options screen.
Most of these settings exist for ensuring compatibility with remote IKE implementations that may have certain
limitations.
•
The Negotiation pop-up menu allows you to specify the way the device will respond to a connection
attempt. Normal (the default) is a two-way mode; Initiate Only or Respond Only permit limiting the
connection to one-way only.
•
The SA Use Policy pop-up menu specifies the policy that the Router will use to determine which Phase 1
SAs to use when multiple valid Phase 1 SAs are available for transmitting traffic on an IPsec tunnel.
Because the Router normally re–keys prior to the expiration of the current Phase 1 SAs, multiple valid
Phase 1 SAs may exist during the period of time after the Router has re-keyed and established new Phase
1 SAs and the time at which the old Phase 1 SAs expire.
•
If you select Newest SAs Immediately, the Router will begin using the newly created Phase 1 SAs
immediately after they are negotiated.
•
If you select Old SAs Until Expired, the Router will continue using the old Phase 1 SAs until they expire
and will begin using the newly created Phase 1 SAs only after the old ones are no longer valid.
•
Allow Dangling Phase 2 SAs toggles whether or not Phase 2 SAs are permitted to survive the expiration of
the Phase 1 SAs under which they were created. Phase 2 SAs "dangle" when the Phase 1 SA under which
they were created expires before they do. There is no requirement that the Phase 1 SA exist for the
duration of the Phase 2 SA's lifetime, but it is convenient because a Delete message may be sent.
•
Phase 1 SA Lifetime (seconds) specifies the duration in seconds for which the SA will remain valid. The
range of permissible values is the set of non-negative integer values between 0 and 2^32-1. The default
value is 28,800 seconds. The value zero specifies the default.
•
Send Initial Contact Message toggles whether or not the IKE negotiation process begins by sending an
initial contact message. The default is Yes.
Advanced IKE Phase 1 Options
Normal
Newest SAs Immediately
No
28800
0
Yes
Yes
Yes
No
No
Need help?
Do you have a question about the Netopia Embedded Software and is the answer not in the manual?
Questions and answers