Configuration
4.10 IPsec Tunnel Configuration
4.10 IPsec Tunnel Configuration
To open the
IPsec Tunnel Configuration
page, click
IPsec
in the
Configuration
section of the
main menu. The menu item will expand and you will see four separate configuration pages:
1st
Tunnel
,
2nd Tunnel
,
3rd Tunnel
and
4th Tunnel
. The IPsec tunnel function allows you to create
a secured connection between two separate LAN networks. The router allows you to create up
to four IPsec tunnels. IPv4 and IPv6 tunnels are supported (dual stack), you can transport IPv6
traffic through IPv4 tunnel and vice versa.
To encrypt data between the local and remote subnets, specify the appropriate values in
the subnet fields on both routers. To encrypt the data stream between the routers only,
leave the local and remote subnets fields blank.
If you specify the protocol and port information in the
Local Protocol/Port
field, then the
router encapsulates only the packets matching the settings.
For optimal setup, we recommend to follow instructions on the web page:
https://wiki.strongswan.org/projects/strongswan/wiki/SecurityRecommendations
Item
Description
Description
Name or description of the tunnel.
Host IP Mode
•
IPv4
– The router communicates via IPv4 with the opposite
side of the tunnel.
•
IPv6
– The router communicates via IPv4 with the opposite
side of the tunnel.
Remote IP Address
IPv4, IPv6 address or domain name of the remote side of the
tunnel, based in the
Host IP Mode
above.
Remote ID
Identifier (ID) of remote side of the tunnel. It consists of two parts:
a
hostname
and a
domain-name
.
Tunnel IP Mode
•
IPv4
– The IPv4 communication runs inside the tunnel.
•
IPv6
– The IPv6 communication runs inside the tunnel.
First Remote Subnet
IPv4 or IPv6 address of a network behind remote side of the
tunnel, based on
Tunnel IP Mode
above.
First Remote Subnet
Mask/Prefix
IPv4 subnet mask of a network behind remote side of the tunnel,
or IPv6 prefix (single number 0 to 128).
Second Remote
Subnet
IPv4 or IPv6 address of the second network behind remote side
of the tunnel, based on
Tunnel IP Mode
above. For
IKE Protocol
= IKEv2 only.
Second Remote
Subnet Mask/Prefix
IPv4 subnet mask of the second network behind remote side of
the tunnel, or IPv6 prefix (single number 0 to 128). For
IKE Pro-
tocol
= IKEv2 only.
Continued on next page
UM Configuration OWL LTE M12
Rel. 06.1.09 - 07/2019
75
Summary of Contents for Hirschmann OWL LTE M12
Page 153: ......