Symantec 360R Administration Guide - Page 201

Table C-29, Field, Description, VPN policies field descriptions, Continued

Page 201 highlights

Field descriptions 201 VPN field descriptions Table C-29 Section VPN policies field descriptions (Continued) Field SA Lifetime Data Volume Limit Inactivity Timeout Perfect Forward Secrecy Description Time, in minutes, before phase 2 renegotiation of new encryption and authentication keys for the tunnel. The default value is 480 minutes. The maximum value is 2,147,483,647 minutes. Maximum number of kilobytes allowed through a tunnel before a rekey is required. The default value is 2100000 KB (2050 MB). The maximum value is 4200000 KB (4101 MB). Number of minutes a tunnel can be inactive before it is re-keyed. Type 0 for no timeout. PFS provides additional protection from attackers trying to guess the current ISKAMP key. Not all clients and security gateways are compatible with Perfect Forward Secrecy. Options include: ■ DH Group 1 ■ DH Group 2 ■ DH Group 5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218

201
Field descriptions
VPN field descriptions
SA Lifetime
Time, in minutes, before phase 2 renegotiation of
new encryption and authentication keys for the
tunnel.
The default value is 480 minutes. The maximum
value is 2,147,483,647 minutes.
Data Volume
Limit
Maximum number of kilobytes allowed through a
tunnel before a rekey is required.
The default value is 2100000 KB (2050 MB). The
maximum value is 4200000 KB (4101 MB).
Inactivity Time-
out
Number of minutes a tunnel can be inactive before
it is re-keyed.
Type 0 for no timeout.
Perfect Forward
Secrecy
PFS provides additional protection from attackers
trying to guess the current ISKAMP key. Not all
clients and security gateways are compatible with
Perfect Forward Secrecy.
Options include:
DH Group 1
DH Group 2
DH Group 5
Table C-29
VPN policies field descriptions
(Continued)
Section
Field
Description