©2015 Cradlepoint. All Rights Reserved.
|
+1.855.813.3385
|
cradlepoint.com
48
User Manual
/
AER3100/AER3150
2. Choose one to be the primary tunnel. Open the editor for this tunnel and make sure
Tunnel Enabled
is
selected. Then go to the
Dead Peer Detection
page. Under
Failover Tunnel
select the other tunnel you
have created.
3. Open the editor for the failover tunnel. Make sure
Tunnel Enabled
is
not
selected. On the
Dead Peer
Detection
page, set the
Failback Tunnel
to your primary tunnel.
Global VPN Settings
These settings apply to all configured VPN tunnels.
Enable VPN Service
: Enabling VPN Service will allow you to load a certificate for VPN to the router.
Certificate Name
: Select the Certificate Name.
IKE / ISAKMP Port
: Internet Key Exchange
/ Internet Security Association and Key
Management Protocol port. (Default: 500. This
is a standard VPN port that usually does not
need to be changed.)
IKE / ISAKMP NAT-T Port
: Internet Key
Exchange / Internet Security Association and
Key Management Protocol network address
translation traversal port. (Default: 4500. This
is a standard VPN NAT-T port that usually does
not need to be changed.)
NAT-T KeepAlive Interval
: Number of seconds between sending NAT-T packets to keep the tunnel alive if no
other traffic is being sent. (Default: 20 seconds. Range: 0-3600 seconds. 20 seconds will be sufficient in almost
all cases.)
Tunnel Connect Retry
: Number of seconds between connection attempts. (Default: 30 seconds. Range: 10-255
seconds. 30 seconds will be sufficient in almost all cases.)
OpenVPN is an open source software application that implements virtual private network (VPN) techniques
for creating secure point-to-point or site-to-site connections in routed or bridged configurations and remote
access facilities.
NOTE:
OpenVPN requires a feature license not included with ECM Prime. Go to
SYSTEM > Administration >
Feature Licenses
to enable this feature.
Once you have a valid feature license, click
Add
to create a new OpenVPN tunnel. Click
Edit
to make changes to
an existing tunnel.
Add/Edit Tunnel – General
•
Tunnel Name
– Enter a name to uniquely identify this tunnel
•
Tunnel Mode
– Select which mode this tunnel endpoint is required to be. Choose from the following:
•
Client
•
Server
•
Device Type -
Select between Routed (TUN) or Bridged (TAP) virtual device.
•
Routed
creates an interface that can be used in the Zone Firewall and is fully routable.
OPEN VPN