beautypg.com

Robustel R3000 User Guide User Manual

Page 74

background image

Robustel GoRugged R3000 User Guide


RT_UG_R3000_v.2.0.0 17.01.2014 73 / 131
Confidential

high confidentiality and security are required.

PFS Group

Select from “PFS_NULL”, “MODP768_1”, “MODP1024_2” and
“MODP1536_5”.
PFS_NULL: Disable PFS Group
MODP768_1: Uses the 768-bit Diffie-Hellman group.
MODP1024_2: Uses the 1024-bit Diffie-Hellman group.
MODP1536_5: Uses the 1536-bit Diffie-Hellman group.

PFS_NULL

Life Time @ SA
Parameter

Set the IPSec SA lifetime.
Note: When negotiating to set up IPSec SAs, IKE uses the smaller one
between the lifetime set locally and the lifetime proposed by the peer.

28800

DPD Time Interval

Set the interval after which DPD is triggered if no IPSec protected
packets is received from the peer.
DPD: Dead peer detection. DPD irregularly detects dead IKE peers.
When the local end sends an IPSec packet, DPD checks the time the last
IPSec packet was received from the peer. If the time exceeds the DPD
interval, it sends a DPD hello to the peer. If the local end receives no
DPD acknowledgment within the DPD packet retransmission interval, it
retransmits the DPD hello. If the local end still receives no DPD
acknowledgment after having made the maximum number of
retransmission attempts, it considers the peer already dead, and clears
the IKE SA and the IPSec SAs based on the IKE SA.

180

DPD Timeout

Set the timeout of DPD packets.

60

Enable Compress

Tick to enable compressing the inner headers of IP packets.

Disable

Enable

ICMP

Detection

Click to enable ICMP detection.

Disable

ICMP

Detection

Server

Enter the IP address or domain name or remote server. Router will ping
this address/domain name to check that if the current connectivity is
active.

Null

ICMP Detection Local
IP

Set the local IP address.

Null

ICMP

Detection

Interval

Set the ping interval time.

30

ICMP

Detection

Timeout

Set the ping timeout.

5

ICMP

Detection

Retries

If Router ping the preset address/domain name time out continuously
for Max Retries time, it will try to re-establish the VPN tunnel.

3