Chapter12 VPN Global Settings
VPN Global Settings
12-24
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Keepalive
Specify the number of seconds that the router should maintain a connection when
it is not being used.
Retry
Specify the number of seconds that the router should wait between attempts to
establish an IKE connection with a peer. The default value is 2 seconds.
DPD Type
Select On Demand or Periodic.
If set to On Demand, DPD messages are sent on the basis of traffic patterns. For
example, if a router has to send outbound traffic and the liveliness of the peer is
questionable, the router sends a DPD message to query the status of the peer. If a
router has no traffic to send, it never sends a DPD message.
If set to Periodic, the router sends DPD messages at the interval specified by the
IKE Keepalive value.
VPN Global Settings: IPSec
Edit global IPSec settings in this window.

Authenticate and Generate new key after every

Check this box and specify the time interval at which the route r should
authenticate and generate a new key. If you do not specify a value, the router will
authenticate and generate a new key every hour.

Generate new key after the current key encrypts a volume of

Check this box and specify the number of kilobytes that should be e ncrypted by
the current key before the router authenticates and generates a new one. If you do
not specify a value, the router will authenticate and generate a new key after the
current key has encrypted 4,608,000 kilobytes.