User`s guide
214
Entity
Instance
Parameter
Values
Equivalent Web Parameter
ike2 n privrsakey Filename RSA private key file
IKEv2 Responder
Configuration - Network > Virtual Private Networking (VPN) > IPsec > IKEv2>
IKEv2 Responder
This page displays the various parameters for IKEv2 0 when used in Responder mode.
Enable IKEv2 Responder
Allows the router to respond to incoming IKE requests.
Accept IKEv2 Requests with
Defines the settings that the router will accept during the negotiation
Encryption
The acceptable encryption algorithms.
Authentication
The acceptable authentication algorithms.
PRF Algorithm
The acceptable PRF (Pseudo Random Function) algorithms.
MODP Group between x and y
The acceptable range for MODP group.
Renegotiate after h hrs m mins s secs
Determines how long the initial IKE Security Association will stay in force. When it expires
any attempt to send packets to the remote system will result in IKE attempting to establish
a new SA.
Rekey after h hrs m mins s secs
When the time left until expiry for this SA reaches the value specified by this parameter, the
IKEv2 SA will be renegotiated, i.e. a new IKEv2 SA is negotiated and the old SA is removed.
Any IPSec “child” SAs that were created are retained and become “children” of the new SA.