P-662H/HW-D Series User’s Guide

When there is outbound traffic but no inbound traffic, the SA times out automatically after two minutes. A tunnel with no outbound or inbound traffic is "idle" and does not timeout until the SA lifetime period expires. See Section 16.6 on page 243on keep alive to have the ZyXEL Device renegotiate an IPSec SA when the SA lifetime expires, even if there is no traffic.

Figure 136 VPN: SA Monitor

The following table describes the fields in this screen.

Table 97 VPN: SA Monitor

LABEL

DESCRIPTION

 

 

No

This is the security association index number.

 

 

Name

This field displays the identification name for this VPN policy.

 

 

Encapsulation

This field displays Tunnel or Transport mode.

 

 

IPSec Algorithm

This field displays the security protocol, encryption algorithm, and authentication

 

algorithm used in each VPN tunnel.

Disconnect

Select one of the security associations, and then click Disconnect to stop that

 

security association.

Refresh

Click Refresh to display the current active VPN connection(s).

 

 

16.17 Configuring Global Setting

To change your ZyXEL Device’s global settings, click VPN and then Global Setting. The screen appears as shown.

Figure 137 VPN: Global Setting

Chapter 16 VPN Screens

261