ProSecure Unified Threat Management (UTM) Appliance

Table 78. IKE policy settings for a Mode Config configuration (continued)

Setting

Description

 

 

 

 

IKE SA Parameters

 

 

Note: Generally, the default settings work well for a Mode Config configuration.

 

 

 

Encryption Algorithm

To negotiate the security association (SA), from the drop-down list, select the

 

3DES algorithm.

 

Authentication

From the drop-down list, select the SHA-1algorithm to be used in the VPN header

Algorithm

for the authentication process.

Authentication Method

Select Pre-shared key as the authentication method, and enter a key in the

 

Pre-shared key field.

 

 

 

 

Pre-shared key

A key with a minimum length of 8 characters and no more than

 

 

49 characters. Do not use a double quote (“) in the key. This

 

 

example uses H8!spsf3#JYK2!.

 

 

 

Diffie-Hellman (DH)

The DH Group sets the strength of the algorithm in bits. From the drop-down list,

Group

select Group 2 (1024 bit).

SA-Lifetime (sec)

The period in seconds for which the IKE SA is valid. When the period times out, the

 

next rekeying occurs. The default setting is 28800 seconds (8 hours). However, for

 

a Mode Config configuration, NETGEAR recommends 3600 seconds (1 hour).

 

 

Enable Dead Peer

Select a radio button to specify whether Dead Peer Detection (DPD) is enabled:

Detection

Yes. This feature is enabled. When the UTM detects an IKE connection failure,

 

it deletes the IPSec and IKE SA and forces a reestablishment of the

Note: See also

connection. You need to specify the detection period in the Detection Period

field and the maximum number of times that the UTM attempts to reconnect in

Configure

the Reconnect after failure count field.

Keep-Alives and

No. This feature is disabled. This is the default setting.

Dead Peer Detection

 

 

on page 328.

Detection Period

The period in seconds between consecutive

 

 

DPD R-U-THERE messages, which are sent only when the

 

 

IPSec traffic is idle. The default setting is 10 seconds. This

 

 

example uses 30 seconds.

 

 

 

 

Reconnect after

The maximum number of DPD failures before the UTM tears

 

failure count

down the connection and then attempts to reconnect to the

 

 

peer. The default setting is 3 failures.

 

 

 

Virtual Private Networking Using IPSec, PPTP, or L2TP Connections

318

Page 318
Image 318
NETGEAR UTM5EW-100NAS, STM150EW-100NAS manual 318, Setting Description IKE SA Parameters, Select Group 2 1024 bit