Note
If the remote party is a SnapGear unit, the ID must have the form abcd@efgh. If the
remote party is not a SnapGear unit, refer the interoperability documents on the SG
Knowledge Base (http://www.cyberguard.com/snapgear/knowledgebase.html) to
determine what form it must take. In this example, enter: branch@office
Leave the IP Payload Compression checkbox unchecked. If compression is selected,
IPComp compression is applied before encryption.
Check the Dead Peer Detection checkbox. This allows the tunnel to be restarted if the
remote party stops responding. This option is only used if the remote party supports
Dead Peer Detection. It operates by sending notifications and waiting for
acknowledgements.
Enter the Delay and Timeout values for Dead Peer Detection. The default times for the
delay and timeout options are 9 and 30 seconds respectively. This means that a Dead
Peer Detection notification is sent every 9 seconds (Delay) and if no response is received
in 30 seconds (Timeout) then the SnapGear unit attempts to restart the tunnel. In this
example, leave the delay and timeout as their default values.
Leave the Initiate Phase 1 & 2 rekeying checkbox checked. This enables automatic
renegotiation of the tunnel when the keys are about to expire.
Click Next to configure the Remote Endpoint Settings.
Other options
Depending on what has been configured previously, the following options become
available:
Route to remote endpoint is the next gateway IP address or nexthop along the
previously selected IPSec interface. This field becomes available if an interface other
than the default gateway was selected for the tunnel to go out on.
SPI Number is the Security Parameters Index. It is a hexadecimal value and must
be unique. It is used to establish and uniquely identify the tunnel. The SPI is used to
determine which key is used to encrypt and decrypt the packets. It must be of the
form 0xhex, where hex is one or more hexadecimal digits and be in the range of
0x100-0xfff. This field appears when Manual Keying has been selected.
Virtual Private Networking
220
Need help?
Do you have a question about the SG300 and is the answer not in the manual?