Appendix B Site-to-Site VPN User Interface Reference

 

 

Site to Site VPN Policies

 

 

Field Reference

Table B-26

Easy VPN Server > Tunnel Group Policy (PIX 7.0/ASA) Page > IPSec Tab

 

 

 

Element

 

Description

 

 

 

Preshared Key

 

The value of the preshared key for the tunnel group. The maximum

 

 

length of a preshared key is 127 characters.

 

 

Trustpoint Name

The trustpoint name if any trustpoints are configured. A trustpoint

 

 

represents a CA/identity pair and contains the identity of the CA,

 

 

CA-specific configuration parameters, and an association with one

 

 

enrolled identity certificate.

 

 

IKE Peer ID Validation

Select whether IKE peer ID validation is ignored, required, or

 

 

checked only if supported by a certificate. During IKE negotiations,

 

 

peers must identify themselves to one another.

 

 

Enable Sending Certificate

When selected, enables the sending of the certificate chain for

Chain

 

authorization. A certificate chain includes the root CA certificate,

 

 

identity certificate, and key pair.

 

 

Enable Password Update with

When selected, enables passwords to be updated with the RADIUS

RADIUS Authentication

authentication protocol.

 

 

For more information, see Supported AAA Server Types,

 

 

page 8-21.

 

 

 

ISAKMP Keepalive

 

 

 

 

Monitor Keepalive

When selected, enables you to configure IKE keepalive as the

 

 

default failover and routing mechanism.

 

 

For more information, see About IKE Keepalive, page 9-69.

 

 

Confidence Interval

The number of seconds that a device waits between sending IKE

 

 

keepalive packets.

 

 

 

Retry Interval

 

The number of seconds a device waits between attempts to establish

 

 

an IKE connection with the remote peer. The default is 2 seconds.

 

 

 

 

 

 

User Guide for Cisco Security Manager 3.0.1

 

 

 

 

 

 

OL-8214-02

 

 

B-79

 

 

 

Page 79
Image 79
3D Innovations 3.0.1 For more information, see Supported AAA Server Types, For more information, see About IKE Keepalive