
Enable Certificate Support
: Enabling Certificate Support will allow you to load a certificate for VPN to the router. Click the “Upload Certificate” button to browse for a
certificate on a local device. Disabling certificate support will no longer use any previously loaded certificate but will not delete it from the router. Only one certificate at a time is
supported.
IKE / ISAKMP Port
: Internet Key Exchange / Internet Security Association and Key Management Protocol port. (Default: 500. This is a standard VPN port that usually does
not need to be changed.)
IKE / ISAKMP NAT-T Port
: Internet Key Exchange / Internet Security Association and Key Management Protocol network address translation traversal port. (Default: 4500.
This is a standard VPN NAT-T port that usually does not need to be changed.)
NAT-T KeepAlive Interval
: Number of seconds between sending NAT-T packets to keep the tunnel alive if no other traffic is being sent. (Default: 20 seconds. Range: 0-
3600 seconds. 20 seconds will be sufficient in almost all cases.)
Tunnel Connect Retry
: Number of seconds between connection attempts. (Default: 30 seconds. Range: 10-255 seconds. 30 seconds will be sufficient in almost all
cases.)
VPN with NAT-T
If one side of a planned VPN tunnel is behind a NAT (network address translation) firewall, the setup of your tunnel requires the following specifications:
1. Each side of the tunnel must use both a
Local Identity
and a
Remote Identity
. These must match the identities on the other side: The Local Identity must match
the Remote Identity on the other side of the tunnel, and vice versa. In this case, these identities can each be a simple word.
2. The
Tunnel Name
for the side of the tunnel that is not behind the NAT firewall must be “anonymous”.
3. The VPN tunnel must be initiated from the side that is behind the NAT firewall.
WAN Affinity / Load Balancing
Load Balance
Select the
Load Balance Algorithm
from the following dropdown options:
Round-Robin
: Evenly distribute each session to the available WAN connections.
Rate
: Distribute load based on the current upload and download rates. A WAN device's upload and download bandwidth values can be set in
Internet
→
Connection Manager
.
Spillover
: This was the default algorithm in older (version 3) firmware. Load is always given to devices with the most available bandwidth. The estimated bandwidth
rate is based on a combination of the upload and download configuration values and the observed capabilities of the device.
Data Usage
: This mode works in concert with the Data Usage feature (
Internet
→
Data Usage
). The router will make a best effort to keep data usage between
CradlePoint COR IBR1100/IBR1150 – Manual
10/13/2014
125