3Com Switch 8800 Family IPsec Module Configuration and Command reference Guide

DVPN Configuration 221
Perform the following configuration in a DVPN policy view.
The default interval for sending keepalive packets is 10 seconds.
Configuring the interval for sending requests to establish a session
If a session is not successfully established, the initiator sends a request again to try
to establish the session after a specific interval. The initiator fails to establish a
session if the session is not established after the initiator sends three successive
requests.
Perform the following configuration in a DVPN policy view.
The default interval for sending requests to establish a session is 10 seconds.
Configuring the IPsec algorithm suite
Packets transmitted in a DVPN domain are IPsec-encrypted for security. At present,
DES, 3DES, and AES encryption algorithms and MD5, SHA1 authentication
algorithms are available. You can specify the algorithm suite used when an IPsec
SA forwards packets by performing the following operations.
Perform the following configuration in a DVPN policy view.
The suite-number parameter is 1 by default, which stands for DES (for encryption)
and MD5 (for authentication).
Configuring the time out time to renegotiate a specified IPsec SA
Perform the following configuration in a DVPN policy view.
Tab le 242 Configure the interval for sending keepalive packets
Operation Command
Configure the interval for sending keepalive
packets
session keepalive-interval time-interval
Revert to the default interval for sending
keepalive packets
undo session keepalive-interval
Tab le 243 Configure the interval for sending requests to establish a session
Operation Command
Configure the interval for sending requests to
establish a session
session setup-interval time-interval
Revert to the default interval for sending
requests to establish a session
undo session setup-interval
Tab le 244 Configure the IPsec algorithm suite
Operation Command
Configure the IPsec algorithm suite data algorithm-suite suite-number
Revert to the default IPsec algorithm suite undo data algorithm-suite