Chapter 18 VPN Screens

When there is outbound traffic but no inbound traffic, the SA times out automatically after two minutes. A tunnel with no outbound or inbound traffic is "idle" and does not timeout until the SA lifetime period expires. See Section 18.6 on page 279on keep alive to have the ZyXEL Device renegotiate an IPSec SA when the SA lifetime expires, even if there is no traffic.

Figure 165 VPN: SA Monitor

The following table describes the fields in this screen.

Table 112 VPN: SA Monitor

LABEL

DESCRIPTION

No

This is the security association index number.

 

 

Name

This field displays the identification name for this VPN policy.

 

 

Encapsulation

This field displays Tunnel or Transport mode.

 

 

IPSec Algorithm

This field displays the security protocol, encryption algorithm, and authentication

 

algorithm used in each VPN tunnel.

 

 

Disconnect

Select one of the security associations, and then click Disconnect to stop that

 

security association.

 

 

Refresh

Click Refresh to display the current active VPN connection(s).

 

 

296

 

P-2602HWLNI User’s Guide