Chapter14 Enhanced Easy VP N
14-8
Cisco Router and Security Device Manager 2.5 User’s Guide
OL-4015-12
Add or Edit Easy VPN Server: IPSec Tab
Enter the information to create an IPSec profile in this dialog. An IPSec profile
specifies the transform sets to be used, how the Security Association (SA) lifetime
is to be determined, and other information.
Dead Peer Discovery Click Dead Peer Discovery to enable the router to send dead peer
detection (DPD) messages to Easy VPN Remote clients. If a client
does not respond to DPD messages, the connection with it is
dropped.
Keepalive Interval—Specify the number of seconds between
DPD messages in the Keepalive Interval field. The range is
from 10 to 3600 seconds.
Retry Interval—Specify the number of seconds between retries
if DPD messages fail in the Retry Interval field. The range is
from 2 to 60 seconds.
Dead peer discovery helps manage connections without
administrator intervention, but it generates additional packets that
both peers must process in order to maintain the connection.
Download user attributes from
RADIUS server based on PKI
certificate fields.
Check this option if you want the Easy VPN server to download
user-specific attributes from the RADIUS server and push them to
the client during mode configuration. The Easy VPN server obtains
the username from the client’s digital certificate.
This option is displayed under the following conditions:
The router runs a Cisco IOS 12.4(4)T or later image.
You choose digital certificate authentication in the IKE policy
configuration.
You choose RADIUS or RADIUS and Local group
authorization.
Table14-2 Add or Edit Easy VPN Server Connection: IKE Tab
Element Description