Digi ConnectPort X4 User's Guide Page 80

  • Download
  • Add to my manuals
  • Print
  • Page
    / 271
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 79
Configuration through the web interface
80
VPN Global Settings
General Security Settings
Enable Antireplay: Antireplay allows the IPsec tunnel receiver to detect and reject
packets that have been replayed. Set this field to match that at the remote VPN gateway.
The default is Enabled.
Important: Disable Antireplay if you use manual keyed tunnels.
Miscellaneous Settings
Suppress SA lifetime during IKE Phase 1: In most cases, leave this option unchecked.
Some VPN equipment does not negotiate the ISAKMP Phase 1 lifetimes. Such
equipment may refuse to negotiate with the Digi device if it includes lifetime values in
Phase 1 negotiation messages. If the Digi device must communicate with such
equipment, enable this option to prevent the Phase 1 lifetimes from being included in
the ISAKMP Phase 1 messages.
Suppress Delete Phase 1 SA Message For PFS: In most cases this option should be
unchecked. VPN devices usually send a delete notification for any phase 2 SAs that are
left over from previous sessions when they start to negotiate quick mode. However,
some devices do not handle this notification correctly and will terminate the connection
when they receive it. If you have trouble connecting to the remote VPN device, you can
try checking this box to suppress sending this message.
IP addresses of remote VPN peers may change on the fly (Dynamic DNS): Check
this box if you are specifying the address of the remote VPN device with a DNS name,
and that device uses dynamic DNS because its public IP address can change. Checking
this box will cause the Digi device to poll the DNS server once a minute to see if the
remote VPN device’s IP address has changed. The IPSec software will be restarted with
the new IP address if it does change. Checking this option will increase network traffic
since the unit will be polling the DNS server once a minute.
Page view 79
1 2 ... 75 76 77 78 79 80 81 82 83 84 85 ... 270 271

Comments to this Manuals

No comments