Cradlepoint COR IBR350 Manual page 113

Hide thumbs Also See for COR IBR350:
Table of Contents

Advertisement

Add/Edit Tunnel – IKE Phase 2 Perfect Forward Secrecy (PFS): Enabling this feature will require IKE to generate a new set of keys in Phase 2
rather than using the same key generated in Phase 1. Additionally, with this option enabled the new keys generated in Phase 2 are exchanged in
an encrypted session. Enabling this feature affords the policy greater security.
Key Lifetime: The lifetime of the generated keys of Phase 2 of the IPsec negotiation from IKE. After the time has expired, IKE will renegotiate a
new set of Phase 2 keys.
Phase 2 has the same selection of Encryption, Hash, and DH Groups as Phase 1, but you are restricted to only one DH Group. Phase 2 and
Phase 1 selections do not have to match.
Add/Edit Tunnel – Dead Peer Detection Dead Peer Detection (DPD) defines how the router will detect when one end of the IPsec session
loses connection while a policy is in use.
Figure 142: Add/Edit VPN Tunnel IKE Dead Peer Detection
Connection Idle Time: Configure how long the router will allow an IPsec session to be idle before beginning to send Dead Peer Detection (DPD)
packets to the peer machine. (Default: 30 seconds. Range: 10 – 3600 seconds.)
113

Advertisement

Table of Contents
loading

Table of Contents