Advanced Settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.40 Locally Managed Administration Guide | 155
VPN Site to Site Global
Settings Attribute
Description
Grace Period after CRL is
no longer valid
CRL grace period is required to resolve the issue of differing
clock times between the appliance and the remote CA.
A grace period permits a wider window for CRL validity.
Indicates the time (in seconds) after which a revoked certificate
of a remote site remains valid.
Grace Period before CRL is
valid
CRL grace period is required to resolve the issue of differing
clock times between the appliance and the remote CA.
A grace period permits a wider window for CRL validity.
Indicates the time window (in seconds) where a certificate is
considered valid prior to the time set by the CA.
IKE DoS from known sites
protection
Indicates if the IKE DoS from known IP addresses protection is
active and the method by which it detects potential attackers.
IKE DoS from unknown
sites protection
Indicates if the IKE DoS from unidentified IP addresses
protection is active and the method by which it detects potential
attackers.
IKE Reply From Same IP
Indicates if the source IP address used in IKE session is based
on destination when replying to incoming connections, or
based on the general source IP address link selection
configuration.
Join adjacent subnets in
IKE Quick Mode
Indicates if to join adjacent subnets in IKE Quick Mode.
Keep DF flag on packet
Indicates if the 'Don't Fragment' flag is kept on the packet
during encryption/decryption.
Keep IKE SA Keys
Keep IKE SA keys.
Key exchange error
tracking
Indicates how to log VPN configuration errors or key exchange
errors.
Match Internet traffic on the
Outgoing Rule Base
Traffic to the Internet from VPN peers that route all their traffic
through this gateway will be matched on the Outgoing Rule
Base.
Maximum concurrent IKE
negotiations
Indicates the maximum number of concurrent VPN IKE
negotiations.
Maximum concurrent
tunnels
Indicates the maximum number of concurrent VPN tunnels.
Open SAs limit
Indicates the maximum number of open SAs per VPN peer.
Outgoing link tracking
Indicates how to log the outgoing VPN link: Log, don't log, or
alert.
Table: VPN Site to Site Global Setting Attributes (continued)