D-Link DFL-260E CLI Guide for DFL-260E - Page 177

Send CRLs in the IKE exchange. Default: Yes

Page 177 highlights

3.52.9. IPsecTunnelSettings Chapter 3. Configuration Reference ICMPSendPerSecLimit SilentlyDropStateICMPErrors Maximum number of ICMP responses that will be sent each second. (Default: 500) Silently drop ICMP errors regarding statefully tracked open connections. (Default: Yes) Note This object type does not have an identifier and is identified by the name of the type only. There can only be one instance of this type. 3.52.9. IPsecTunnelSettings Description Settings for the IPsec tunnel interfaces used for establishing IPsec VPN connections to and from this system. Properties IPsecMaxTunnels IPsecMaxRules IKESendInitialContact IKESendCRLs IKECRLValidityTime IKEMaxCAPath IPsecCertCacheMaxCerts IPsecBeforeRules IPsecGWNameCacheTime DPDMetric FlowMetric IPsecDPDNoWaitWorryTime Amount of IPsec tunnels allowed (0 = automatic). (Default: 0) Amount of IPsec rules allowed (0 = automatic). (Default: 0) Send 'initial contact' messages. (Default: Yes) Send CRLs in the IKE exchange. (Default: Yes) Maximum number of seconds a CRL is considered valid (0=obey the 'next update' field in the CRL). (Default: 86400) Maximum number of CA certificates in a certificate path. (Default: 15) Maximum number of entries in the certificate cache. (Default: 1024) Pass IKE & IPsec (ESP/AH) traffic sent to the security gateway directly to the IPsec engine without consulting the ruleset. (Default: Yes) Amount of time to keep an IPsec tunnel open when the remote DNS name fails to resolve. (Default: 14400) Metric 10s of seconds with no traffic or other evidence of life in tunnel before SA is removed. (Default: 3) Minimum number of seconds without data traffic in a flow to activate IKE DPD liveness checks from the corresponding IKE SA. (Default: 15) Do not wait for 10 times the value of DPD Metric after the value of Flow Metric has expired without 177

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198

ICMPSendPerSecLimit
Maximum number of ICMP responses that will be
sent each second. (Default: 500)
SilentlyDropStateICMPErrors
Silently
drop
ICMP
errors
regarding
statefully
tracked open connections. (Default: Yes)
Note
This object type does not have an identifier and is identified by the name of the type
only. There can only be one instance of this type.
3.52.9. IPsecTunnelSettings
Description
Settings for the IPsec tunnel interfaces used for establishing IPsec VPN connections to and from this
system.
Properties
IPsecMaxTunnels
Amount of IPsec tunnels allowed (0 = automatic).
(Default: 0)
IPsecMaxRules
Amount of IPsec rules allowed (0 = automatic).
(Default: 0)
IKESendInitialContact
Send 'initial contact' messages. (Default: Yes)
IKESendCRLs
Send CRLs in the IKE exchange. (Default: Yes)
IKECRLValidityTime
Maximum number of seconds a CRL is considered
valid (0=obey the 'next update' field in the CRL).
(Default: 86400)
IKEMaxCAPath
Maximum number of CA certificates in a certificate
path. (Default: 15)
IPsecCertCacheMaxCerts
Maximum number of entries in the certificate cache.
(Default: 1024)
IPsecBeforeRules
Pass IKE & IPsec (ESP/AH) traffic sent to the secur-
ity gateway directly to the IPsec engine without con-
sulting the ruleset. (Default: Yes)
IPsecGWNameCacheTime
Amount of time to keep an IPsec tunnel open when
the remote DNS name fails to resolve. (Default:
14400)
DPDMetric
Metric 10s of seconds with no traffic or other evid-
ence
of
life
in
tunnel
before
SA
is
removed.
(Default: 3)
FlowMetric
Minimum number of seconds without data traffic in
a flow to activate IKE DPD liveness checks from the
corresponding IKE SA. (Default: 15)
IPsecDPDNoWaitWorryTime
Do not wait for 10 times the value of DPD Metric
after the value of Flow Metric has expired without
3.52.9. IPsecTunnelSettings
Chapter 3. Configuration Reference
177