Billion 810VGTX Router
Page | 87
Type: Check Dial Out if you want your router to operate as a client (connecting to a remote VPN server, e.g. your office
server), check Dial In if you want your router to operate as a VPN server.
When configuring your router as a Client, enter the remote Server IP Address (or Hostname) you wish to
connect to.
When configuring your router as a server, enter the Private IP Address Assigned to the Dial in User.
IP Address: Enter the IP address.
Username: If you are a Dial-Out user (client), enter the username provided by your Host. If you are a Dial-In user
(server), enter your own username.
Password: If you are a Dial-Out user (client), enter the password provided by your Host. If you are a Dial-In user
(server), enter your own password.
Authentication Type: Default is ‘Auto’ if you want the router to determine the authentication type to use, or else
manually specify CHAP (Challenge Handshake Authentication Protocol) or PAP (Password Authentication Protocol) if
you know which type the server is using (when acting as a client), or else the authentication type you want clients
connecting to you to use (when acting as a server). When using PAP, the password is sent unencrypted, whilst CHAP
encrypts the password before sending, and also allows for challenges at different periods to ensure that an intruder has
not replaced the client.
Tunnel Authentication: This enables the router to authenticate both the L2TP remote and L2TP host. This is only valid
when L2TP remote supports this feature.
Secret: The secure password length should be 16 characters which may include numbers and characters.
Active as default route: Commonly used by the Dial-out connection, all packets will route through the VPN tunnel to the
Internet; therefore, activating the function may degrade Internet performance.
Remote Host Name (Optional): Enter the hostname of the remote VPN device. It is a tunnel identifier to check if the
Remote VPN device matches with the Remote hostname provided. If the remote hostnames match, the tunnel will be
connected; otherwise, it will be dropped.
Caution: This only applies when the router is acting as a VPN server. This option should be used by advanced
users only.
Local Host Name (Optional): Enter the hostname of a Local VPN device that is connected / established a VPN tunnel.
By default, the router’s default Hostname is home.gateway.
IPSec: Enable to enhance your L2TP VPN security.
Authentication: Authentication establishes the integrity of the datagram and ensures it is not tampered with during
transmission. There are three options, Message Digest 5 (MD5), Secure Hash Algorithm (SHA1) or NONE. SHA1 is
more resistant to brute-force attacks than MD5, however it is slower.
MD5: A one-way hashing algorithm that produces a 128−bit hash.
SHA1: A one-way hashing algorithm that produces a 160−bit hash.
Encryption: Select the encryption method from the pull-down menu. There are four options, DES, 3DES, AES and
NULL. NULL means it is a tunnel with no encryption. 3DES and AES are more powerful but increase latency.
DES: Stands for Data Encryption Standard, it uses 56 bits as an encryption method.
3DES: Stands for Triple Data Encryption Standard, it uses 168 (56*3) bits as an encryption method.
AES: Stands for Advanced Encryption Standards, it uses 128 bits as an encryption method.