Index |
A unique index identifying this entry. Range: 1 to -1 |
Description |
An optional description for this profile. Length: 0 to 255 |
Proposal |
The index of the first IKE proposal which may be used for IKE SA negotiation with this profile. |
BlockTime |
This object specifies the time in seconds for which a peer is blocked for any IPSec operations after a phase 1 initiator negotiation failed. Special values: -1: use settings from global profile (do not block by default) 0: do not block the peer at all. Range: -1 to 86400 |
NatT |
This object specifies whether NAT-Traversal is enabled Possible values: enabled(1), -- enable Nat-Traversal disabled(2), -- disable Nat-Traversal default(3) -- use value from default profile -- (disabled, if this is the default profile). Enumerations: - enabled (1)
- disabled (2)
- default (3)
- delete (4)
|
MtuMax |
The maximum MTU value allowed for ipsecPeerMtu. This variable affects only peers with ipsecPeerStatIpVersion 'ipv4'. Zero means use value from global profile, if this is the global profile, 1418 is assumed. Nonzero values smaller than 214 are reset to the minimum of 214. Range: 0 to 65535 |
LifeSeconds |
The time (in seconds) after which an SA will be rekeyed. |
AliveCheck |
This object specifies if a check is done to see whether the other endpoint is alive. (only for IKEv2). Enumerations: |
Ip6MtuMax |
The maximum MTU value allowed for ipsecPeerStatMtu. This variable affects only peers with ipsecPeerStatIpVersion 'ipv6' while ikePrfMtuMax affects peers with ipsecPeerStatIpVersion 'ipv4'. Zero means use value from global profile, if this is the global profile, 1398 is assumed. Nonzero values smaller than 214 are reset to the minimum of 214. |
LifeRekeyPercent |
The percentage of the lifetime after which rekeying is started. Range: 50 to 100 |