Configure Virtual Private Networking (VPN)
IPsec parameters
Digi TransPort WR Routers User Guide
446
MODECFG Static NAT mappings parameters
MODECFG is an extra stage built into IKE negotiations that fits between IKE phase 1 and IKE phase 2.
It performs operations such as extended authentication (XAUTH) and requesting an IP address from
the host. This IP address becomes the source address to use when sending packets through the
tunnel from the remote to the host. This mode of operation, receiving one IP address from the
remote host, is called client mode. Another mode, network mode, allows the router to send packets
with a range of source addresses through the tunnel.
If the router receives packets from a local interface that need to be routed through the tunnel, it
performs address translation so the source address matches the assigned IP address before
encrypting using the negotiated SA. Some state information is retained so that packets coming in
the opposite direction with matching addresses/ports can have their destination address set to the
source address of the original packet, in the same way as standard NAT.
If the remote end of the tunnel can access units connected to the local interface, the unit that has
been assigned the virtual IP address needs to have some static NAT entries set up. When a packet is
received through the tunnel, the router first looks up existing NAT entries, followed by static NAT
entries to determine whether the destination address/port should be modified, and forwards the
packet to the new address. If a static NAT mapping is found, the router creates a dynamic NAT entry
it uses for the duration of the connection. If no dynamic or stateful entry is found, the packet is
directed to the local protocol handlers.
External Port
The lowest destination port number to be matched if the packet is redirected.
Forward to Internal IP Address
An IP address to which packets containing the specified destination port number are redirected.
Forward to Internal Port
A port number to which packets containing the specified destination port number are
redirected.
Port Range Count
The number of ports to be matched.
Add button
Adds the static NAT mapping to the IPsec tunnel configuration.
Summary of Contents for TransPort WR11
Page 1: ...User Guide Digi TransPort WR Routers ...
Page 650: ...Configure system settings NTP parameters Digi TransPort WR Routers User Guide 650 ...
Page 661: ...Configure system settings General system parameters Digi TransPort WR Routers User Guide 661 ...
Page 662: ...Configure system settings General system parameters Digi TransPort WR Routers User Guide 662 ...
Page 663: ...Configure system settings General system parameters Digi TransPort WR Routers User Guide 663 ...
Page 682: ...Configure Remote Management SNMP parameters Digi TransPort WR Routers User Guide 679 ...
Page 683: ...Configure Remote Management SNMP parameters Digi TransPort WR Routers User Guide 680 ...
Page 813: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 808 ...
Page 814: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 809 ...
Page 815: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 810 ...
Page 816: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 811 ...
Page 817: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 812 ...
Page 818: ...Manage networks and connections Top Talkers Digi TransPort WR Routers User Guide 813 ...
Page 855: ...Device administration Reboot the router Digi TransPort WR Routers User Guide 844 ...