
ICR-1601
136
Tunnel Configuration Window
Item
Value setting
Description
Tunnel
Unchecked by
default
Check the Enable box to activate the IPSec tunnel
Tunnel Name
1. A Must fill setting
2. String format can
be any text
Enter a tunnel name. Enter a name that is easy for you to identify.
Value Range: 1 ~ 19 characters.
Interface
1. A Must fill setting
2. WAN 1 is selected
by default
Select the interface on which IPSec tunnel is to be established. It can be the
available WAN and LAN interfaces.
Tunnel Scenario
1. A Must fill setting
2. Site to site is
selected by default
Select an IPSec tunneling scenario from the dropdown box for your
application. Select Site-to-Site, Site-to-Host, Host-to-Site, or Host-to-Host. If
LAN interface is selected, only Host-to-Host scenario is available.
With Site-to-Site or Site-to-Host or Host-to-Site, IPSec operates in tunnel
mode. The difference among them is the number of subnets. With Host-to-
Host, IPSec operates in transport mode.
Tunnel TCP MSS
1. An optional
setting
2. Auto is set by
default
Select from the dropdown box to define the size of Tunnel TCP MSS.
Select Auto, and all devices will adjust this parameter automatically.
Select Manual, and specify an expected value for Tunnel TCP MSS.
Value Range: 64 ~ 1500 bytes.
Hub and Spoke
1. An optional
setting
2. None is set by
default
Select from the dropdown box to setup your router for Hub-and-Spoke IPSec
VPN Deployments.
Select None if your deployments will not support Hub or Spoke encryption.
Select Hub for a Hub role in the IPSec design.
Select Spoke for a Spoke role in the IPSec design.
Note: Hub and Spoke are available only for Site-to-Site VPN tunneling
specified in Tunnel Scenario.