54
User
Manual
GWG Gateway
Key File
Select which key file to use.
CA Certificate
Select which CA certificate file to use.
Local Client Certificate
Select which Local Client Certificate file to use.
Local Client Key
Select which Local Client Key file to use.
Enable IKE failover
Enable IKE failover option which tries periodically to establish security association.
IKE SA retry
Number of IKE retries, before failover.
Enable Tunnel Failover
Enables tunnel failover. If there is more than one tunnel defined, this option will
failover to other tunnel in case that selected one fails to establish connection.
Ping IP or Hostname
IP address on other side of tunnel which will be pinged in order to determine
current state.
Ping interval
Specify time period in seconds between two pings.
Packet size
Specify size of data field in IP packet for ping message.
Maximum number of
failed packets
Set percentage of failed packets until failover action is performed.
Compress (Support IP
Payload Compression
Protocol (IP Comp))
IP Payload Compression is a protocol that reduces the size of IP datagram. Select
this option if you want the GWG Gateway to propose compression when it initiates
a connection.
Dead Peer Detection
(DPD)
When DPD is enabled, the Geneko Router will send periodic HELLO/ACK
messages to check the status of the IPSec tunnel (this feature can be used only when
both peers or IPSec devices of the IPSec tunnel use the DPD mechanism). Once a
dead peer has been detected, the Geneko Router will disconnect the tunnel so the
connection can be re-established. Specify the interval between HELLO/ACK
messages (how often you want the messages to be sent). The default interval is 20
seconds.
NAT Traversal
Both the IPSec initiator and responder must support the mechanism for detecting
the NAT gateway in the path and changing to a new port, as defined in RFC 3947.
NOTE: Keep-alive for NAT-T function is enabled by default and cannot be disabled.
The default interval for keep-alive packets is 20 seconds.
Send initial contact
The initial contact status message may be used when one side wishes to inform the
other that this is the first SA being established with the remote system.The receiver
of this Notification Message might then elect to delete any existing SA's.
Back
Click
Back
to return on IPSec Summary screen.
Reload
Click
Reload
to discard any changes and reload previous settings.
Save
Click
Save
to save your changes back to the GWG Gateway. After that router goes
back and begin negotiations of the tunnels by clicking on the
Start
.
Table
13
– IPSec Parameters
Summary of Contents for GWG
Page 1: ...GWG Gateway USER MANUAL GWG Document version 1 0 1 Date July 2016 WWW GENEKO RS ...
Page 43: ...43 User Manual GWG Gateway Figure 22 RIP configuration page ...
Page 136: ...136 User Manual GWG Gateway Click OK Figure 125 Policies from trust to untrust zone ...
Page 156: ...156 User Manual GWG Gateway Figure 150 Configuration page for SIM keepalive ...