User Guide
OmniAccess 3500 Nonstop Laptop Guardian Administration Guide
AH SPI-In — Security Parameter Index found in incoming IPsec packets
with AH protection (not available with ESP protection).
AH SPI-Out — Security Parameter Index inserted in outgoing IPsec
packets with AH protection (not available with ESP protection).
Algorithm Cipher — Algorithm used for the encryption of packets
exchanged over the IPsec tunnel.
Algorithm Hash — Algorithm used for the exchange of credentials over
the IPsec tunnel.
− Flows — [Gateway|Configure Advanced Settings|Flows], [Gateway:->
Flows], [r]
List of the objects that the OmniAccess 3500 NLG gateway instantiates for
stateful packet inspection purposes. When a packet arrives at the firewall
embedded in the OmniAccess 3500 NLG gateway, the firewall first tries to
match it with a previously established flow object. If no matching flow
object is found, the firewall tries to match the packet with one of its
configured rules. If one or more matches are found, a new flow object is
created according to the matching rule with the highest precedence. If no
matching rule is found, the default rule (drop) is applied to the packet and
no new flow is created. Each row in the table corresponds to one stateful-
inspection flow object and shows the following information items:
Idle Time — Time elapsed since the last packet associated with the flow
was received (in seconds).
IP Protocol — IP-encapsulated protocol of the connection associated
with the flow object. Some of the possible values are <TCP>, <UDP>,
<ESP>, <AH>.
Source IP — Source IP Address (outer IP header) identifying the flow
object.
Source Port — Source Port (if protocol is TCP or UDP) identifying the
flow object.
Dest. IP — Destination IP Address (outer IP header) identifying the flow
object.
Dest. Port — Destination Port (if protocol is TCP or UDP) identifying the
flow object.
Rule Index — Internal identifier of the rule that originated the flow
object.
− Global Information — [Gateway|Configure Advanced Settings|Global
Information], [Gateway: -> Global Information], [r]
List of statistics collected since the OmniAccess 3500 NLG gateway was last
restarted and current status indicators.
Active IKE SAs — Number of IKE Security Associations that are currently
active.
92