
Configuring a VPN Security Association 125
Check the Disable all Windows Networking (NetBIOS) Broadcasts check
box to disable NetBIOS traffic. Click the Update buttontosaveyour
changes.
Enable Fragmented Packet Handling
Check the Enable Fragmented Packet Handling box to allow the Firewall
to reduce that packet size when communicating with other Firewalls.
Enable this check box if “Fragmented IPSec packet dropped” messages
appear in the Event Log. Click the Update button to save your changes.
Viewing the Current
IPSec Security
Associations
The Current IPSec Security Associations section of the VPN Summary
screen shows all Security Associations (SAs) that have been created in the
VPN Configure window. The Name listed in the summary table links to
the corresponding VPN configuration.
A Renegotiate button will appear next to an IKE VPN Security Association
when the VPN connection is active. Click the Renegotiate button to
initiate the VPN handshake and the exchange of new encryption and
authentication keys.
The SuperStack 3 Firewall will support 1000 SAs. Of these SAs, 999 will
support a single VPN tunnel, while the remaining single SA can support
up to 100 concurrent VPN tunnels. This is called the “GroupVPN” SA.
Configuring a VPN
Security
Association
To configure the VPN Security Associations click on VPN andthenselect
the Configure tab. A window similar to that in Figure 57 displays.
DUA1611-0AAA02.book Page 125 Thursday, August 2, 2001 4:01 PM
Kommentare zu diesen Handbüchern