|
Setting/Setting Confirmation
223
ALL:ALL
0.0.0.0/0 or not specified
(blank)
0.0.0.0/0 or not specified
(blank)
*When all Internet traffic is made to the IPsec tunnel.
■
Rekey timing
Rekey timing of IKE SA/IPsec SA is determined from the IKE Phase 1/Phase 2 lifetime.
Furthermore, rekey timing is determined at random between 70% to 85% of the lifetime.
*Lifetime of IKE_SA_INIT exchange/IKE_AUTH exchange is applicable to IKEv2
[Example]
When IKE Phase 1 lifetime is 28,800 seconds
28800 x 0.70 = 20160 seconds [Minimum value]
Rekey is executed during this time.
28800 x 0.85 = 24480 seconds [Maximum value]
■
Local and remote IDs of IKE v1 IKE Phase 1/Phase 2 are treated as follows.
IKE (IKE Phase1)
IPsec (IKE Phase2)
Phase
Mode
Behavior
Peer
Direction
local-id
remote-id local-id
remote-id
IKE
Phase1
(=Ph1)
main
mode
initiator
1
Send
Send in sequence
5
Not sent
Receive
from peer
Compare with
remote-id of local
station.
Unused
responder 1
Send
Send in sequence
6
Not sent
Receive
from peer
Compare with
remote-id of local
station.
Unused
aggressive
mode
initiator
1
Send
Send in sequence
1
Not sent
Receive
from peer
Compare with
remote-id of local
station.
Unused
responder 1
(any)
*
Send
Send in sequence
2
Not sent
Receive
from peer
Compare with
remote-id of local
station.
Unused