9. In Advanced Options, configure the following:
• DHCP Option 43 Sub Code for Security Gateway: Set the DHCP Option 43 subcode
that will be used to discover the address of the security gateway on the network. The
default subcode is 7.
• Retry Limit: Set the number of times that the controller will attempt to discover the address
of the security gateway. The default retry count is 5. Accepted values are 0 (disable) to
16.
• Replay Window: Set the ESP replay window (in packets). The default size is 32 packets.
Accepted values are 0 (disable) to 32 packets.
• IP Compression: To enable IP Payload Compression Protocol (IPComp) compression
before encryption, click Enable. The default value is Disable.
• Force NAT-T: To enforce UDP encapsulation of ESP packets, click Enable. The default
value is Disable.
• Dead Peer Detection: By default, the IKE protocol runs a health check with remote peer
to ensure that it is alive. To disable this health check, click Disable.
• NAT-T Keep Alive Interval: To set the keep alive interval (in seconds) for NAT traversal,
type a value in the box. The default keep alive interval is 20 seconds. Accepted values are
1 to 65536. To disable the keep alive interval, click Disable.
• FailOver Options: To configure the failover settings when APs are unable to connect,
configure the following:
• Retry Period: Set the number of days (minimum 3 days) during which APs will keep
attempting to connect. To keep try indefinitely, select the Forever check box.
• Retry Interval: Set the interval (in minutes) between each retry attempt. The default
retry interval is 1 minute. Accepted values are from 1 to 30 minutes.
• Retry Mode: If you want APs to fall back to the specified primary security gateway,
click Revertive. If you want APs to maintain connectivity with the security gateway to
which they are currently connected, click Non-revertive.
10. Click .
SmartCell Gateway 200/Virtual SmartZone High-Scale for Release 3.4.1 Administrator Guide
107
Managing Global Configuration, AP Tunnel Profiles, Templates, and AP Registration Rules
Creating AP Tunnel Profiles