Motorola 6161252-00-01, Enterprise Series Routers manual Options

Models: Enterprise Series Routers 6161252-00-01

1 340
Download 340 pages 8.06 Kb
Page 184
Image 184

6-8 Administrator’s Handbook

Advanced IKE Phase

1 Options

Negotiation...

Normal

SA Use Policy...

Newest SAs Immediately

Allow Dangling Phase 2 SAs:

No

Phase 1 SA Lifetime (seconds):

28800

Phase 1 SA Lifetime (Kbytes):

0

Send Initial Contact Message:

Yes

Include Vendor ID Payload:

Yes

Independent Phase 2 Re-keys:

Yes

Strict Port Policy:

No

Invalid SPI recovery:

No

Traffic based Dead Peer Detection:

Yes

DPD Keepalive Idle Time (seconds):

20

Return/Enter to select <among/between> ...

 

Normally it is not necessary to change the settings of the items on the Advanced IKE Phase 1 Options screen. Most of these settings exist for ensuring compatibility with remote IKE implementations that may have certain limitations.

The Negotiation pop-up menu allows you to specify the way the device will respond to a connection attempt. Normal (the default) is a two-way mode; Initiate Only or Respond Only permit limiting the connection to one-way only.

The SA Use Policy pop-up menu specifies the policy that the Router will use to determine which Phase 1 SAs to use when multiple valid Phase 1 SAs are available for transmitting traffic on an IPsec tunnel.

Because the Router normally re–keys prior to the expiration of the current Phase 1 SAs, multiple valid Phase 1 SAs may exist during the period of time after the Router has re-keyed and established new Phase 1 SAs and the time at which the old Phase 1 SAs expire.

If you select Newest SAs Immediately, the Router will begin using the newly created Phase 1 SAs immediately after they are negotiated.

If you select Old SAs Until Expired, the Router will continue using the old Phase 1 SAs until they expire and will begin using the newly created Phase 1 SAs only after the old ones are no longer valid.

Allow Dangling Phase 2 SAs toggles whether or not Phase 2 SAs are permitted to survive the expiration of the Phase 1 SAs under which they were created. Phase 2 SAs “dangle” when the Phase 1 SA under which they were created expires before they do. There is no requirement that the Phase 1 SA exist for the duration of the Phase 2 SA’s lifetime, but it is convenient because a Delete message may be sent.

Phase 1 SA Lifetime (seconds) specifies the duration in seconds for which the SA will remain valid. The range of permissible values is the set of non-negative integer values between 0 and 2^32-1. The default value is 28,800 seconds. The value zero specifies the default.

Send Initial Contact Message toggles whether or not the IKE negotiation process begins by sending an initial contact message. The default is Yes.

Page 184
Image 184
Motorola 6161252-00-01, Enterprise Series Routers manual Options