ZyXEL MAX318M User Guide - Page 142

IPSec VPN: Add continued, Remote Endpoint, Single address, Subnet address, Remote, Endpoint

Page 142 highlights

Chapter 8 Security Table 60 IPSec VPN: Add (continued) LABEL SA Life Time Dead Peer Detection (DPD) DESCRIPTION Type the maximum number of seconds the IKE SA can last. When this time has passed, the WiMAX Device and remote IPSec router have to update the encryption and authentication keys and re-negotiate the IKE SA. This does not affect any existing IPSec SAs, however. Select this check box if you want the WiMAX Device to make sure the remote IPSec router is there before it transmits data through the IKE SA. The remote IPSec router must support DPD. If the remote IPSec router does not respond, the WiMAX Device shuts down the IKE SA. DPD Interval DPD Idle Try Local Network If the remote IPSec router does not support DPD, see if you can use the VPN connection connectivity check. Specify the time interval for the WiMAX Device to send a DPD message to the remote IPSec router. Specify the maximum number of times the WiMAX Device sends the DPD message. Local IP addresses must be static and correspond to the remote IPSec router's configured remote IP addresses. Two active SAs can have the same configured local or remote IP address, but not both. You can configure multiple SAs between the same local and remote IP addresses, as long as only one is active at any time. In order to have more than one active rule with the Remote Endpoint field set to 0.0.0.0, the ranges of the local IP addresses cannot overlap between rules. Address Type Start IP Address If you configure an active rule with 0.0.0.0 in the Remote Endpoint field and the LAN's full IP address range as the local IP address, then you cannot configure any other active rules with the Remote Endpoint field set to 0.0.0.0. Select Single address or Subnet address to specify if the VPN connection begins at an IP address or subnet. If Single address is selected, enter a (static) IP address on the LAN behind your WiMAX Device. Subnet Mask Local Port If Subnet address is selected, specify IP addresses on a network by their subnet mask by entering a (static) IP address on the LAN behind your WiMAX Device. Then enter the subnet mask to identify the network address. If Subnet address is selected, enter the subnet mask to identify the network address. Select how the WiMAX Device checks the connection. The peer must be configured to respond to the method you select. Select icmp to have the WiMAX Device regularly ping the address you specify to make sure traffic can still go through the connection. You may need to configure the peer to respond to pings. Remote Network Select tcp or udp to have the WiMAX Device regularly perform a TCP or UDP handshake with the address you specify to make sure traffic can still go through the connection. You may need to configure the peer to accept the TCP or UDP connection. If you select tcp or udp, specify the port number to use for the connectivity check. Remote IP addresses must be static and correspond to the remote IPSec router's configured local IP addresses. The remote fields do not apply when the Remote Endpoint field is configured to 0.0.0.0. In this case only the remote IPSec router can initiate the VPN. Two active SAs cannot both have the same local and remote IP address(es). Two active SAs can have the same local or remote IP address, but not both. You can configure multiple SAs between the same local and remote IP addresses, as long as only one is active at any time. 142 WiMAX Device Configuration User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290

Chapter 8 Security
WiMAX Device Configuration User’s Guide
142
SA Life Time
Type the maximum number of seconds the IKE SA can last. When this time has
passed, the WiMAX Device and remote IPSec router have to update the
encryption and authentication keys and re-negotiate the IKE SA. This does not
affect any existing IPSec SAs, however.
Dead Peer
Detection
(DPD)
Select this check box if you want the WiMAX Device to make sure the remote
IPSec router is there before it transmits data through the IKE SA. The remote
IPSec router must support DPD. If the remote IPSec router does not respond,
the WiMAX Device shuts down the IKE SA.
If the remote IPSec router does not support DPD, see if you can use the VPN
connection connectivity check.
DPD Interval
Specify the time interval for the WiMAX Device to send a DPD message to the
remote IPSec router.
DPD Idle Try
Specify the maximum number of times the WiMAX Device sends the DPD
message.
Local Network
Local IP addresses must be static and correspond to the remote IPSec router's
configured remote IP addresses.
Two active SAs can have the same configured local or remote IP address, but not
both. You can configure multiple SAs between the same local and remote IP
addresses, as long as only one is active at any time.
In order to have more than one active rule with the
Remote Endpoint
field set
to 0.0.0.0, the ranges of the local IP addresses cannot overlap between rules.
If you configure an active rule with 0.0.0.0 in the
Remote Endpoint
field and
the LAN’s full IP address range as the local IP address, then you cannot configure
any other active rules with the
Remote Endpoint
field set to 0.0.0.0.
Address Type
Select
Single address
or
Subnet address
to specify if the VPN connection
begins at an IP address or subnet.
Start IP
Address
If
Single address
is selected, enter a (static) IP address on the LAN behind your
WiMAX Device.
If
Subnet address
is selected, specify IP addresses on a network by their
subnet mask by entering a (static) IP address on the LAN behind your WiMAX
Device. Then enter the subnet mask to identify the network address.
Subnet Mask
If
Subnet address
is selected, enter the subnet mask to identify the network
address.
Local Port
Select how the WiMAX Device checks the connection. The peer must be
configured to respond to the method you select.
Select
icmp
to have the WiMAX Device regularly ping the address you specify to
make sure traffic can still go through the connection. You may need to configure
the peer to respond to pings.
Select
tcp
or
udp
to have the WiMAX Device regularly perform a TCP or UDP
handshake with the address you specify to make sure traffic can still go through
the connection. You may need to configure the peer to accept the TCP or UDP
connection. If you select
tcp
or
udp
, specify the port number to use for the
connectivity check.
Remote Network
Remote IP addresses must be static and correspond to the remote IPSec router's
configured local IP addresses. The remote fields do not apply when the
Remote
Endpoint
field is configured to 0.0.0.0. In this case only the remote IPSec
router can initiate the VPN.
Two active SAs cannot both have the same local and remote IP address(es). Two
active SAs can have the same local or remote IP address, but not both. You can
configure multiple SAs between the same local and remote IP addresses, as long
as only one is active at any time.
Table 60
IPSec VPN: Add (continued)
LABEL
DESCRIPTION