16.11.2012 Views

tainy hmod-v3-io, tainy hmod-l3-io - Dr. Neuhaus ...

tainy hmod-v3-io, tainy hmod-l3-io - Dr. Neuhaus ...

tainy hmod-v3-io, tainy hmod-l3-io - Dr. Neuhaus ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

VPN connect<strong>io</strong>ns<br />

ISAKMP-SA mode Agree with the administrator of the remote stat<strong>io</strong>n which method will be used<br />

for negotiating the ISAKMP-SA. The following select<strong>io</strong>ns are available:<br />

ISAKMP-SA lifetime<br />

IPsec-SA<br />

lifetime<br />

� Main mode<br />

� Aggressive mode<br />

Note:<br />

When the authenticat<strong>io</strong>n method Pre-Shared Key is used, Aggressive mode<br />

must be set in Roadwarr<strong>io</strong>r mode.<br />

The keys for an IPsec connect<strong>io</strong>n are renewed at certain intervals in order to<br />

increase the effort required to attack an IPsec connect<strong>io</strong>n.<br />

Specify the lifetime (in seconds) of the keys agreed on for the ISAKMP-SA<br />

and IPsec-SA.<br />

The lifetime can be defined differently for ISAKMP-SA and IPsec-SA.<br />

NAT-T There may be a NAT router between the TAINY xMOD-V3-IO and the VPN<br />

gateway of the remote network. Not all NAT routers allow IPsec data packets<br />

to go through. It may therefore be necessary to encapsulate the IPsec data<br />

packets in UDP packets so that they can go through the NAT router.<br />

Enable<br />

dead peer detect<strong>io</strong>n<br />

On: If the TAINY xMOD-V3-IO detects a NAT router that does not<br />

let the IPsec data packets through, then UDP encapsulat<strong>io</strong>n is<br />

started automatically.<br />

Force: During negotiat<strong>io</strong>n of the connect<strong>io</strong>n parameters for the VPN<br />

connect<strong>io</strong>n, encapsulated transmiss<strong>io</strong>n of the data packets<br />

during the connect<strong>io</strong>n is insisted upon.<br />

Off: The NAT-T funct<strong>io</strong>n is switched off<br />

If the remote stat<strong>io</strong>n supports the dead peer detect<strong>io</strong>n (DPD) protocol, then<br />

the partner in quest<strong>io</strong>n can detect whether the IPsec connect<strong>io</strong>n is still valid<br />

or not, meaning that it may have to be re-established. Without DPD,<br />

depending on the configurat<strong>io</strong>n it may be necessary to wait until the SA<br />

lifetime elapses or the connect<strong>io</strong>n has to be re-initiated manually. To check<br />

whether the IPsec connect<strong>io</strong>n is still valid, the dead peer detect<strong>io</strong>n sends<br />

DPD requests to the remote stat<strong>io</strong>n itself. If there is no answer, then after the<br />

permitted number of failed attempts the IPsec connect<strong>io</strong>n is considered to be<br />

interrupted.<br />

Warning<br />

Sending the DPD requests and using NAT-T increases the amount of data<br />

sent and received over the mobile data service connect<strong>io</strong>n (HSPA+, UMTS,<br />

EGPRS, GPRS). Depending on the selected settings, the addit<strong>io</strong>nal data<br />

traffic can amount to 5 Mbyte per month or more. This can lead to addit<strong>io</strong>nal<br />

costs.<br />

Yes Dead peer detect<strong>io</strong>n is switched on. Independently of the<br />

transmiss<strong>io</strong>n of user data, the TAINY xMOD-V3-IO detects if<br />

the connect<strong>io</strong>n is lost, in which case it waits for the connect<strong>io</strong>n<br />

to be re-established by the remote stat<strong>io</strong>ns.<br />

No Dead peer detect<strong>io</strong>n is switched off<br />

DPD - delay (seconds) Time per<strong>io</strong>d in seconds after which DPD requests will be sent. These<br />

requests test whether the remote stat<strong>io</strong>n is still available.<br />

DPD - timeout<br />

(seconds)<br />

Time per<strong>io</strong>d in seconds after which the connect<strong>io</strong>n to the remote stat<strong>io</strong>n will<br />

be declared dead if no response has been made to the DPD requests.<br />

TAINY xMOD Page 63 of 111

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!