Configure the device using the Digi ConnectPort X Family web interface
Configuration through the web interface
Digi ConnectPort X Family
76
Use the Digi device for primary or backup remote site connectivity. The Digi device routes secured
IPsec VPN traffic over the cellular IP network and a VPN appliance terminates it at the host end.
You can use a VPN-enabled Digi device in several scenarios; for example:
n
As the
primary
router where the remote site does not use another WAN router.
n
As a
backup
router where the remote site has a primary WAN connection through DSL, Frame
Relay, or other means.
n
To provide secure access to remote serial and/or Ethernet devices.
This section describes using a Digi device as a
primary
remote site router using IPsec Encapsulated
Security Payload (ESP) and Internet Key Exchange (IKE)/Internet Security Association and Key
Management Protocol (ISAKMP) pre-shared key methods.
VPN global settings
n
General Security Settings
l
Enable Antireplay
: Antireplay allows the IPsec tunnel receiver to detect and reject
packets that have been replayed. Set this field to match that at the remote VPN gateway.
The default is Enabled.
Important
Disable Antireplay if you use manual keyed tunnels.
n
Miscellaneous Settings
l
Suppress SA lifetime during IKE Phase 1
: In most cases, clear this check box. Some VPN
equipment do not negotiate the ISAKMP Phase 1 lifetimes. Such equipment may refuse to
negotiate with the Digi device if it includes lifetime values in Phase 1 negotiation
messages. If the Digi device must communicate with such equipment, enable this option to
prevent the Phase 1 lifetimes from being included in the ISAKMP Phase 1 messages.
l
Suppress Delete Phase 1 SA Message For PFS
: In most cases clear this check box. VPN
devices usually send a delete notification for any phase 2 SAs that are left over from
previous sessions when they start to negotiate quick mode. However, some devices do not
handle this notification correctly and will terminate the connection when they receive it. If
you have trouble connecting to the remote VPN device, select this check box to suppress
sending this message.
l
IP addresses of remote VPN peers may change on the fly (Dynamic DNS)
: Enable when
you are specifying the address of the remote VPN device with a DNS name, and that device
uses dynamic DNS because its public IP address can change. Selecting this check box will
cause the Digi device to poll the DNS server once a minute to see if the remote VPN
device’s IP address has changed. The IPsec software will be restarted with the new IP
address if it does change. Selecting this check box increases network traffic since the unit
will be polling the DNS server once a minute.