Specifications

Motorola Solutions AP-7131N-FGR Access Point Product Reference Guide
6-32
The Inbound and Outbound SPI settings are required to be interpolated to function correctly.
For example:
AP1 Inbound SPI = 800
AP1 Outbound SPI = 801
AP2 Inbound SPI = 801
AP2 Outbound SPI = 800
4. Click Ok to return to the VPN screen. Click
Apply
to retain the settings made on the Manual
Key Settings screen.
5. Click Cancel to return to the VPN screen without retaining the changes made to the
Manual Key Settings screen.
6.7.3 Configuring Auto Key Settings
The access point’s Network Management System can automatically set encryption and
authentication keys for VPN access. Use the Auto Key Settings screen to specify the type of
encryption and authentication, without specifying the keys. To manually specify keys, cancel out of
the Auto Key Settings screen, select the Manual Key Exchange radio button, and set the keys
within the Manual Key Setting screen.
To configure auto key settings for the access point:
1. Select Network Configuration -> WAN -> VPN from the access point menu tree.
2. Refer to the VPN Tunnel Config field, select the Auto (IKE) Key Exchange radio button
and click the Auto Key Settings button.
3. Configure the Auto Key Settings screen to modify the following:
Use Perfect Forward
Secrecy
Forward secrecy is a key-establishment protocol guaranteeing the
discovery of a session key or long-term private key does not
compromise the keys of other sessions. Select Yes to enable
Perfect Forward Secrecy. Select No to disable Perfect Forward
Secrecy.
Security Association
Life Time
The Security Association Life Time is the configurable interval used
to timeout association requests that exceed the defined interval.
This is an IPsec Phase 2 SA lifetime having the default value of 300
seconds. The configurable range is from 300 to 28800 seconds.