Configuring ike dpd – H3C Technologies H3C SecPath F1000-E User Manual
Page 704
7
Item
Description
SA Lifetime
Type the ISAKMP SA lifetime of the IKE proposal.
Before an SA expires, IKE negotiates a new SA. As soon as the new SA is set up, it takes
effect immediately and the old one will be cleared automatically when it expires.
IMPORTANT:
If the SA lifetime expires, the system automatically updates the ISAKMP SA. As DH
calculation in IKE negotiation takes time, especially on low-end devices, it is
recommended to set the lifetime greater than 10 minutes to prevent the SA update
from influencing normal communication.
.
Configuring IKE DPD
Select VPN > IKE > DPD from the navigation tree to display existing DPDs, as shown in
. Then,
click Add to enter the DPD configuration page, as shown in
.
Figure 6 DPD list
Figure 7 Add an IKE DPD
describes the configuration items for creating an IKE DPD.
Table 4 IKE DPD configuration items
Item
Description
DPD Name
Type a name for the IKE DPD.
DPD Query
Triggering Interval
Type the interval after which DPD is triggered if no IPsec protected packets is received
from the peer.