User`s guide
208
Entity
Instance
Parameter
Values
Equivalent Web Parameter
ike n dpd on, off Enable Dead Peer Detection
ike n natt on, off Enable NAT-Traversal
ike n initialcontact on, off
Send INITIAL-CONTACT
notifications
ike n keepph1 on, off
Retain phase 1 SA after failed
phase 2 negotiation
ike n privrsakey Filename RSA private key file
ike n delmode
0 = Normal
1 = Remove IKE
SA when last IPsec
SA removed
2 = Remove IPsec
SAs when IKE SA
remove
3 = Both
SA Removal Mode
ike n openswan on, off
None. This enables support for
Openswan IKE implementations.
IKE Responder
Configuration - Network > Virtual Private Networking (VPN) > IPsec > IKE> IKE
Responder
This page displays the various parameters for IKE 0 when used in Responder mode.
Enable IKE Responder
Allows the router to respond to incoming IKE requests.
Accept IKE Requests with
Defines the settings that the router will accept during the negotiation
Encryption
The acceptable encryption algorithms.
Authentication
The acceptable authentication algorithms.
MODP Group between x and y
The acceptable range for MODP group.
Renegotiate after h hrs m mins s secs
Determines how long the initial IKE Security Association will stay in force. When it expires
any attempt to send packets to the remote system will result in IKE attempting
to establish a new SA.
Related CLI Commands
Entity
Instance
Parameter
Values
Equivalent Web Parameter
ike 0 noresp on, off Enable IKE Responder