To configure an IPsec IKE policy
Steps
1 |
Choose Policies→ISA Policies→IPsec Policies from the NFM-P main menu. The IPsec Policies form opens. |
2 |
Click Create→IKE Policy, or choose a policy and click Properties. The IPsec IKE Policy (Create|Edit) form opens. |
3 |
Configure the required parameters on the General tab. |
4 |
Click on the NAT Traversal tab and configure the required parameters. |
5 |
Click on the DPD tab and configure the required parameters. The Interval and Max Retries parameters can only be configured when the Dead Peer Detection (DPD) parameter is set to Enable. |
6 |
Click on the Lockout tab and configure the required parameters. If you select the Enable Lockout check box, you can configure a set of parameters that define the lockout condition. |
7 |
If applicable, click on the IKE Transforms tab and associate IKE Transform policies to the IKE policy. Depending on the NE software release, up to four IKE Transform policies may be applicable. Perform the following steps:
|
8 |
If the IKE version is v2, the Fragment tab becomes available. If you select the Fragment check box, you can configure a set of parameters that define the fragmentation. |
9 |
Click Apply. |
10 |
Distribute the policy to NEs. |
11 |
Close the IPsec IKE Policy (Create|Edit) form. |
12 |
Close the IPsec Policies form. End of steps |