
6-6
VPN 3002 Hardware Client Reference, Release 4.0
OL-3813-01
Chapter 6 Tunneling
Configuration | System | Tunneling Protocols | IPSec
Alert when disconnecting
The VPN 3002 notifies the VPN Concentrator at the central site of sessions that are about to be
disconnected from its side of the connection, and conveys the reason. The VPN Concentrator decodes
the reason, and displays it in the event log or in a pop-up screen. The feature is enabled by default. This
screen lets you disable the feature so that the VPN 3002 does not send or receive alerts.
Uncheck the box to disable alerts.
• The VPN 3002 no longer sends alerts when it disconnects sessions.
• The VPN 3002 does not receive alerts when the VPN Concentrator at the central site disconnects
sessions.
Note To send and receive alerts, the VPN 3002 and the VPN Concentrator to which the VPN 3002 connects
must be running software version 4.0 or greater, and must have the feature enabled.
IPSec over TCP
Check IPSec over TCP if you want to connect using IPSec over TCP. This feature must also be enabled
on the VPN Concentrator to which this VPN 3002 connects. See the explanation that follows.
IPSec over TCP Port
Enter the IPSec over TCP port number. You can enter one port. The port that you configure on the VPN
3002 must also match that configured on the VPN Concentrator to which this VPN 3002 connects.
About IPSec over TCP
IPSec over TCP encapsulates encrypted data traffic within TCP packets. This feature enables the VPN
3002 to operate in an environment in which standard Encapsulating Security Protocol (ESP, Protocol 50)
or Internet Key Exchange (IKE, UDP 500) cannot function, or can function only with modification to
existing firewall rules. IPSec over TCP encapsulates both the IKE and IPSec protocols within a TCP
packet, and enables secure tunneling through both NAT and PAT devices and firewalls.
Note This feature does not work with proxy-based firewalls.
The VPN 3002 Hardware Client, which supports one tunnel at a time, can connect using either standard
IPSec, IPSec over TCP, or IPSec over UDP or IPSec over NAT-T.
To use IPSec over TCP, both the VPN 3002 and the VPN Concentrator to which it connects must be
running version 3.5 software.
Comentarios a estos manuales