DIR-822
AC1200 Wave 2 MU-MIMO Wi-Fi EasyMesh Router
User Manual
Configuring via Web-based Interface
Parameter
Description
Local WAN
A WAN connection through which the tunnel will pass. Select a value
from the drop-down list.
•
Interface
:
When this value is selected, the
Interface
drop-
down list is displayed. Select an existing WAN connection
from the list.
•
Default gateway
: When this value is selected, the router uses
the default WAN connection.
Local identifier
A local identifier of the router to establish connection over IPsec with
particular hosts only. To establish connection, DIR-822 local identifier
value should correspond to the remote identifier value specified in the
settings of the remote host. Use an IP address, domain name, or
certificate CN.
Optional.
Local port
A port of the router, that is used for IPsec packets exchange during the
First Phase of the connection. If the field is left blank, port 500 is used.
If the field is left blank and the network address translation (NAT)
function is used for the connection, port 4500 is used.
NAT Traversal
The NAT Traversal function allows VPN traffic to pass through the
NAT-enabled device. DIR-822 allows to forcibly encapsulate VPN
traffic in UDP packets for passing through a remote device regardless
of whether it supports address translation.
If you need to enable forced encapsulation of VPN traffic, select the
Enabled
value.
If you need to disable forced encapsulation of VPN traffic, select the
Disabled
value
.
Mode
An operation mode of the IPsec tunnel. Select a value from the drop-
down list.
•
TUNNEL
: As a rule, it is used to create a secure connection to
remote networks. In this mode, the source IP packet is fully
encrypted and added to a new IP packet and data transfer is
based on the header of the new IP packet.
•
TRANSPORT
: As a rule, it is used to encrypt data stream
within one network. In this mode, only the content of the
source IP packet is encrypted, its header remains unchanged
and data transfer is based on the source header.
Allow traffic from
IPsec to router
Move the switch to the left to deny access to your router from the
remote subnet via IPsec. The switch is displayed when the
TUNNEL
value is selected from the
Mode
drop-down list.
Page
173
of 235