16.11.2012 Views

tainy hmod-v3-io, tainy hmod-l3-io - Dr. Neuhaus ...

tainy hmod-v3-io, tainy hmod-l3-io - Dr. Neuhaus ...

tainy hmod-v3-io, tainy hmod-l3-io - Dr. Neuhaus ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

VPN connect<strong>io</strong>ns<br />

Retry count This parameter determines the number of allowed failed ping transmiss<strong>io</strong>n<br />

retries before the VPN client inside the TAINY HMOD-V3-IO will be<br />

restarted.<br />

Target hosts Tunnel<br />

name<br />

Host IP<br />

address<br />

Client IP<br />

address<br />

Determine, which VPN connect<strong>io</strong>n (VPN tunnel) shall be<br />

supervised. Add a VPN connect<strong>io</strong>n by clicking the New button,<br />

delete a VPN connect<strong>io</strong>n by clicking the Delete button.<br />

Enter the IP address of the remote stat<strong>io</strong>n (target host) here.<br />

Enter here any unused IP address of the local network related<br />

to the VPN connect<strong>io</strong>n.<br />

Factory setting The factory settings used by the TAINY xMOD-V3-IO are as follows:<br />

Enable VPN supervis<strong>io</strong>n Nein<br />

Connect<strong>io</strong>n check interval (minutes) 5<br />

Retry delay (minutes) 1<br />

Retry count 3<br />

7.7 Advanced settings for VPN connect<strong>io</strong>ns<br />

IPsec VPN ><br />

Advanced settings<br />

ONLY TAINY HMOD-V3-IO<br />

ONLY TAINY EMOD-V3-IO<br />

Funct<strong>io</strong>n Setting special timeouts and intervals for VPN connect<strong>io</strong>ns.<br />

NAT-T keepalive interval<br />

(seconds)<br />

Phase 1 timeout<br />

(seconds)<br />

Phase 2 timeout<br />

(seconds)<br />

Number of connects<br />

attempts until restart of<br />

the VPN client<br />

If NAT-T is enabled (cf. Chapter 7.3), then keepalive data packets will be<br />

sent per<strong>io</strong>dically by the TAINY xMOD-V3-IO through the VPN connect<strong>io</strong>n.<br />

The purpose of this is to prevent a NAT router between the TAINY xMOD-<br />

V3-IO and the remote stat<strong>io</strong>n from interrupting the connect<strong>io</strong>n during idle<br />

per<strong>io</strong>ds without data traffic.<br />

Here you can change the interval between the keepalive data packets.<br />

The Phase 1 timeout determines how long the TAINY xMOD-V3-IO waits for<br />

complet<strong>io</strong>n of an authenticat<strong>io</strong>n process of the ISAKMP-SA. If the set<br />

timeout is exceeded, the authenticat<strong>io</strong>n will be aborted and restarted.<br />

Here you change the timeout.<br />

The Phase 2 timeout determines how long the TAINY xMOD-V3-IO waits for<br />

complet<strong>io</strong>n of an authenticat<strong>io</strong>n process of the IPsec-SA. If the set timeout is<br />

exceeded, the authenticat<strong>io</strong>n will be aborted and restarted.<br />

Here you change the timeout.<br />

If the establishment of a VPN connect<strong>io</strong>n fails, the connect<strong>io</strong>n setup will be<br />

retried by the TAINY xMOD-V3-IO. Enter the number of unsuccessful retries,<br />

being performed before the TAINY xMOD-V3-IO restart its VPN client before<br />

trying again the connect<strong>io</strong>n setup.<br />

Page 74 of 111 TAINY xMOD

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!