12-23
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Chapter12 VPN Global Settings
VPN Global Settings
IPSec Security Association (SA) Lifetime (Kilobytes)
The number of kilobytes that the router can send over the VPN connection be fore
the IPSec SA expires. The SA will be renewed after the shortest lifetimes is
reached.
VPN Global Settings: IKE
This window lets you specify global settings for IKE and IPSEC.
Enable IKE
Leave this box checked if you want to use VPN.
Caution If IKE is disabled, VPN configurations will not work.
Enable Aggressive mode
The Aggressive Mode feature allows you to specify RADIUS tunnel attributes for
an IPSec peer and to initiate an IKE aggressive mode negotiation with the tunnel
attributes.
Identity (of this router)
This field specifies the way the router will identify itself. Select either IP address
or host name.
XAuth Timeout
The number of seconds the router is to wait for a response from a system requiring
XAuth authentication.
Enable Dead Peer Detection (DPD)
Dead Peer Detection (DPD) enables a router to detect a dead peer and, if detected,
delete the IPSec and IKE security associations with that peer.
The Enable Dead Peer Detection checkbox is disabled when the Cisco IOS image
that the router is using does not support DPD.