User`s guide
Chapter 12 VPN Global Settings
VPN Global Settings
12-24
Cisco Router and Security Device Manager Version 2.2 User’s Guide
OL-4015-08
Keepalive
Specify the number of seconds that the router should maintain a connection when
it is not being used.
Retry
Specify the number of seconds that the router should wait between attempts to
establish an IKE connection with a peer. The default value is ‘2’ seconds.
DPD Type
Select On Demand or Periodic.
If set to On Demand, DPD messages are sent on the basis of traffic patterns. For
example, if a router has to send outbound traffic and the liveliness of the peer is
questionable, the router sends a DPD message to query the status of the peer. If a
router has no traffic to send, it never sends a DPD message.
If set to Periodic, the router sends DPD messages at the interval specified by the
IKE Keepalive value.
VPN Global Settings: IPSec
Edit global IPSec settings in this window.
Authenticate and Generate new key after every
Check this box and specify the time interval at which the router should
authenticate and generate a new key. If you do not specify a value, the router will
authenticate and generate a new key every hour.
Generate new key after the current key encrypts a volume of
Check this box and specify the number of kilobytes that should be encrypted by
the current key before the router authenticates and generates a new one. If you do
not specify a value, the router will authenticate and generate a new key after the
current key has encrypted 4,608,000 kilobytes.