Chapter 6

Advanced Features

Dead Peer Detection The SpeedTouch™ supports the Dead Peer Detection protocol.

By default, the use of this protocol is enabled. This option allows disabling the use of the DPD protocol.

DPD

Possible values

default value

 

 

 

 

enabled

enabled

 

disabled

 

 

 

 

DPD Idle Period The DPD protocol defines a worry period. This is an idle time during which no IPSec traffic is detected from the remote peer. At the expiry of this period the local peer transmits a number of R-U-THERE messages to detect the liveliness of the remote peer.

This option sets the duration of the idle period, expressed in seconds.

dpd_idle_period

Unit

default value

 

 

 

 

seconds

180

 

 

 

DPD number of Transmits

This option determines the number of R-U-THERE transmitted by the local peer. If none of these messages is acknowledged in due time by the remote peer, it is decided that the remote peer is dead.

dpd_xmits

default value

 

 

 

3

 

 

DPD Timeout This option determines the timeout value for the R-U-THERE messages. Within this period an R-U-THERE acknowledge message from the remote peer is expected.

dpd_timeout

Unit

default value

 

 

 

 

seconds

120

 

 

 

Tunnel inactivity timeout When no traffic is detected at the peer for a certain period, it is decided that the tunnel is not used any more, and the IKE session is terminated. All IPSec connections supported by the IKE session are terminated as well.

This option sets the value of the inactivity timer.

inactivity

Unit

default value

 

 

 

 

seconds

3600

 

 

 

202

E-DOC-CTC-20051017-0169 v0.1

 

Page 204
Image 204
Nortel Networks 620, 608(WL) manual Dpdidleperiod Unit Default value, DPD number of Transmits, Dpdxmits Default value