Appendix B Site-to-Site VPN User Interface Reference

Site to Site VPN Policies

Table B-16

VPN Global Settings Page > ISAKMP/IPSec Settings Tab (continued)

 

 

 

Element

 

Description

 

 

SA Requests System Limit

Supported on routers running IOS version 12.3(8)T and later, except

 

 

7600 routers.

 

 

The maximum number of SA requests allowed before IKE starts

 

 

rejecting them.

 

 

You can enter a value in the range of 0-99999.

 

 

Note Make sure the specified value equals or exceeds the number

 

 

of peers, or the VPN tunnels may be disconnected.

 

 

SA Requests System Threshold

Supported on Cisco IOS routers and Catalyst 6500/7600 devices.

 

 

The percentage of system resources that can be used before IKE

 

 

starts rejecting new SA requests.

 

 

Enable Aggressive Mode

Supported on ASA devices and PIX 7.0 devices.

 

 

When selected, enables you to use aggressive mode in ISAKMP

 

 

negotiations, for an ASA device. Aggressive mode is enabled by

 

 

default.

 

 

Deselect this check box to disable the use of aggressive mode in

 

 

ISAKMP negotiations, for an ASA device.

 

 

See Understanding IKE, page 9-58.

 

 

 

IPSec Settings

 

 

 

 

 

Enable Lifetime

 

When selected, enables you to configure the global lifetime settings

 

 

for the crypto IPSec security associations (SAs) on the devices in

 

 

your VPN topology.

 

 

 

Lifetime (secs)

 

The number of seconds a security association will exist before

 

 

expiring. The default is 3,600 seconds (one hour).

 

 

Lifetime (kbytes)

The volume of traffic (in kilobytes) that can pass between IPSec

 

 

peers using a given security association before it expires. The

 

 

default is 4,608,000 kilobytes.

 

 

 

 

User Guide for Cisco Security Manager 3.0.1

B-46

OL-8214-02

Page 46
Image 46
3D Innovations 3.0.1 appendix See Understanding IKE