Netgear FVS318 FVS318v3 Reference Manual - Page 86

Deactivating a VPN Tunnel, Using the Policy Table on the VPN Policies to Deactivate a VPN Tunnel

Page 86 highlights

Reference Manual for the ProSafe VPN Firewall FVS318v3 • Click Clear Log to delete all log entries. 3. Click VPN Status (Figure 5-37) to get the Current VPN Tunnels (SAs) screen (Figure 5-38). Figure 5-38: Current VPN Tunnels (SAs) screen This page lists the following data for each active VPN Tunnel. • SPI-each SA has a unique SPI (Security Parameter Index) for traffic in each direction. For Manual key exchange, the SPI is specified in the Policy definition. For Automatic key exchange, the SPI is generated by the IKE protocol. • Policy Name-the name of the VPN policy associated with this SA. • Remote Endpoint-the IP address on the remote VPN Endpoint. • Action-the action will be either a Drop or a Connect button. • SLifeTime (Secs)-the remaining Soft Lifetime for this SA in seconds. When the Soft Lifetime becomes zero, the SA (Security Association) will re-negotiated. • HLifeTime (Secs)-the remaining Hard Lifetime for this SA in seconds. When the Hard Lifetime becomes zero, the SA (Security Association) will be terminated. (It will be re-established if required.) Deactivating a VPN Tunnel Sometimes a VPN tunnel must be deactivated for testing purposes. There are two ways to deactivate a VPN tunnel: • Policy table on VPN Policies page • VPN Status page Using the Policy Table on the VPN Policies Page to Deactivate a VPN Tunnel To use the VPN Policies page to deactivate a VPN tunnel, perform the following steps: 1. Log in to the VPN Firewall. 2. Click on VPN Policies under VPN to get the VPN Policies screen below (Figure 5-39). 5-30 January 2005 Basic Virtual Private Networking

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242

Reference Manual for the ProSafe VPN Firewall FVS318v3
5-30
Basic Virtual Private Networking
January 2005
Click
Clear Log
to delete all log entries.
3.
Click
VPN Status
(
Figure 5-37
) to get the Current VPN Tunnels (SAs) screen (
Figure 5-38
).
Figure 5-38:
Current VPN Tunnels (SAs) screen
This page lists the following data for each active VPN Tunnel.
SPI
—each SA has a unique SPI (Security Parameter Index) for traffic in each direction.
For Manual key exchange, the SPI is specified in the Policy definition. For Automatic key
exchange, the SPI is generated by the IKE protocol.
Policy Name
—the name of the VPN policy associated with this SA.
Remote Endpoint
—the IP address on the remote VPN Endpoint.
Action
—the action will be either a
Drop
or a
Connect
button.
SLifeTime (Secs)
—the remaining Soft Lifetime for this SA in seconds. When the Soft
Lifetime becomes zero, the SA (Security Association) will re-negotiated.
HLifeTime (Secs)
—the remaining Hard Lifetime for this SA in seconds. When the Hard
Lifetime becomes zero, the SA (Security Association) will be terminated. (It will be
re-established if required.)
Deactivating a VPN Tunnel
Sometimes a VPN tunnel must be deactivated for testing purposes. There are two ways to
deactivate a VPN tunnel:
Policy table on VPN Policies page
VPN Status page
Using the Policy Table on the VPN Policies Page to Deactivate a VPN Tunnel
To use the VPN Policies page to deactivate a VPN tunnel, perform the following steps:
1.
Log in to the VPN Firewall.
2.
Click on
VPN Policies
under VPN to get the VPN Policies screen below (
Figure 5-39
).