Draytek vigor3900 User Manual page 297

Multi-wan security appliance
Hide thumbs Also See for vigor3900:
Table of Contents

Advertisement

Phase 1 Key Life
Time
Phase 2 Key Life
Time
Perfect Forward
Secrecy Status
Dead Peer
Detection Status
DPD Delay
DPD Timeout
Source IP
5.
After filling the required information for Advanced, click the GRE tab to open the
following page.
Available parameters are listed as follows:
Vigor3900 Series User's Guide
The rekey-renegotiated period of the IKE Phase1 keying
channel of a connection. The acceptable range is from 5 to
480 minutes (8 hours).
The rekey-renegotiated period of the IKE Phase 2 keying
channel of a connection. The acceptable range is from 5 to
480 minutes (8 hours).
Enables the PFS function. A new Diffie-Hellman Key
Exchange is included every time an encryption and/or
authentication key are computed on PFS.
Enable – Click it to enable DPD. When there is no traffic
through the IPSec tunnel, both server and the client will send
the DPD packet to each other to ensure the IPSec tunnel
connection is active still.
Disable – Click it to disable DPD.
The keep-alive timer. A Hello message will be emitted
periodically when a tunnel is idle. Use the value 0 to disable
this function. The recommended value is 30 seconds if
enabled.
The timeout timer. The peer will be declared dead once no
acknowledge message is received after timeout value. Use
the value 0 to disable this function. The recommended value
is 120 seconds if enabled.
Choose one of the LAN profiles as a source IP.
289

Advertisement

Table of Contents
loading

Table of Contents