Virtual Private Networking Using IPSec and L2TP Connections
262
ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
Figure 173.
4. In the IKE SA Parameters section of the screen, locate the DPD fields, and complete the
settings as explained the following table:
5. Click Apply to save
your settings.
Configure NetBIOS Bridging with IPSec VPN
Windows networks use the Network Basic Input/Output System (NetBIOS) for several basic
network services such as naming and neighborhood device discovery. Because VPN routers
do not usually pass NetBIOS traffic, these network services do not function for hosts on
opposite ends of a VPN connection. To solve this problem, you can configure the VPN
firewall to bridge NetBIOS traffic over the VPN tunnel.
To enable NetBIOS bridging on a configured VPN tunnel:
1. Select VPN > IPSec VPN > VPN Policies. The
VPN Policies screen displays (see
Figure 156 o
n page 232).
Table 64. Dead Peer Detection settings
Setting Description
IKE SA Parameters
Enable Dead Peer
De
tection
Select the Yes radio button to enable DPD. When the VPN firewall detects an
IKE connection failure, it deletes the IPSec and IKE SA and forces a
reestablishment of the connection. You need to specify the detection period in
the Detection Period field and the maximum number of times that the VPN
firewall attempts to reconnect in the Reconnect after failure count field.
Detection Period The period in seconds between consecutive
DPD R-U-THERE messages, which are sent only when the
IPSec traf
fic is idle. The default setting is 10 seconds.
Reconnect after
fai
lure count
The maximum number of DPD failures before the VPN
firewall tears down the connection and then attempts to
reconnect to the peer. The default setting is 3 failures.