EasyManuals Logo

GE MDS ORBIT ECR User Manual

GE MDS ORBIT ECR
463 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #260 background imageLoading...
Page #260 background image
260 MDS Orbit MCR/ECR Technical Manual MDS 05-6632A01, Rev. F
The following table describes the VPN connection attempt retries and time interval between them. After
giving up as listed below, the unit waits for “failure-retry-interval” and repeats the connection attempt
sequence.
Table 3-19. VPN Connection Retry
Attempt#
Relative Timeout
Between Attempts (secs)
Absolute Timeout
From First Attempt (secs)
1
0
0
2 (1
st
retry)
4
4
3 (2
nd
retry)
7
11
4 (3
rd
retry)
13
24
5 (4
th
retry)
23
47
6 (5
th
retry)
42
89
Give up
76
165
Wait for “failure-retry-interval”, then repeat above sequence
During initial configuration set failure-retry-interval to lowest value of 1 min, to have Orbit attempt
connection more quickly. This allows debugging of any connection-related issue by watching logs on
peer side etc. Be sure to change this value to 5 minutes or higher to prevent excessive attempts and traffic.
Commit configuration to save the changes.
% commit
Following shows IKE policy configuration for public-key encryption based authentication method:
Create IKE policy with auth-method “public-key encryption”. 1.
% set services vpn ike policy IKE-POLICY-1 auth-method pub-key
Configure Public Key Infrastructure (PKI) security credentials. 2.
d. Certificate type as “rsa” if RSA public key encryption based certificates are being used.
e. Client certificate ID This is the ID that was assigned to the client certificate obtained via
SCEP or loaded manually (assumed to be ID-1).
f. Client private key ID This is the ID that was assigned to the client private key generated
during SCEP procedure or loaded manually (assumed to be ID-1).
g. Certificate Authority (CA) certificate ID This is the ID that was assigned to the CA certificate
obtained via SCEP or loaded manually (assumed to be CA-1).
% set services vpn ike policy IKE-POLICY-1 pki cert-type rsa
% set services vpn ike policy IKE-POLICY-1 pki cert-id ID-1
% set services vpn ike policy IKE-POLICY-1 pki key-id ID-1
% set services vpn ike policy IKE-POLICY-1 pki ca-cert-id CA-1
Firewall Configuration
The VPN wizard automatically configures the firewall to allow incoming and outgoing IKE/IPsec traffic
over the Cell/WAN interface. However, when VPN is configured manually via Services->VPN->Basic
Config menu or via CLI, the firewall needs to be manually configured as well:
1. Add following rules to IN_UNTRUSTED filter that is applied to the Cell interface in the incoming
direction:
% set services firewall filter IN_UNTRUSTED rule 1 match protocol icmp

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the GE MDS ORBIT ECR and is the answer not in the manual?

GE MDS ORBIT ECR Specifications

General IconGeneral
BrandGE
ModelMDS ORBIT ECR
CategoryNetwork Router
LanguageEnglish

Related product manuals