Manual

Table Of Contents
Software User Guide 80
Network Tab
TunnelType:Controlstheinitialmodeofthetunnelatstartup.TheoptionsgiventoIPsecwillbe:
Client:auto=start
Server:auto=add
Dynamic:auto=route
Formoreinformation,pleaseconsultanIPsecuserguideonaspectsofthesespecificmodes.
NegotiationMode:Asadefault,thisfieldissettoMainmodeISAKMPNegotiation.Whenusingdynamic,orDHCP
issuedIPaddresses(forexamplewithcellularcards),someremotedevicesmayrequiretheuseofAggressive
Mode
ISAKMPNegotiation.Shouldyouencounterthissituation,youcanperformaggressivemodeISAKMPnegotiationby
changingthisparameterfrom“Main”toAggressiveISAKMP”.TouseAggressiveISAKMPNegotiations,selectYesfrom
thelistprovidedorNotopreventit’suse.
DeadPeerDetectionAction:Thisfeaturecanhelpdetectwhen
aremoteendpointisnolongercommunicatingprop
erly.Onceanerrorisdetecte d,the“hold”statewillonlyrenegotiatethetunnelafternewtrafficdestinedforthetun
nelisdetected.The“restartstatewillattempttoimmediatelyreestablishtheconnectiontotheconcentrator.For
thisreason,“restart ”
mayusemorebandwidthandmaynotbetheidealchoiceforalimiteddataplan.However,ifa
hostatthecentralsiteneedstoinitiateconnectionsdowntoalocaldevicethroughthetunnel,“restart”maybenec
essarysothatthetunnelisalwaysupandwaiting
fornewdatafromtheconcentrator.
UsePerfectForwardSecrecy:SpecifieswhetherornotthetunnelwillusePerfectForwardSecrecywhennegotiation
cryptographyparameterswiththeremotedevice.Note:Thisparametermustbesetthesameonthedevicesonboth
sidesofthetunnelinorderforaSecurity
Association(SA)tobeestablished.Th isisoneofthefirstthingsthatshould
becheckedwhentunnelnegotiationdifficultiesareencountered.
ClickontheNEXTbuttonandthefollowingEncryptionSettingsdialogwindowwillappear:
Phase1Encryption:Selectthetypeofencryptionneededforphase1(IKE).
Phase1Authentication:
Selectthetypeofauthenticationneededforphase1(IKE).