
IPSec
76
System Administrator’s Guide
2. Select the
Enable IPSec
option.
3. Select the type of IPSec endpoint the Shiva VPN Gateway will create on the
Internet port. The Shiva VPN Gateway can either have a static IP, dynamic IP or
DNS hostname address. If a dynamic DNS service is to be used or there is a
DNS hostname that resolves to the IP address on the Internet port, then the DNS
hostname address option should be selected. For this example, select
dynamic
IP address
.
4. The Maximum Transmission Unit (MTU) of the IPSec interface can be configured
by selecting the
Set the IPSec MTU to be
option and filling in the desired MTU
value. For most applications this does not need to be configured. However, if set,
the MTU value should be between 1400 and 1500.
5. Click the
Apply
button to save the changes.
Warning:
It may be necessary to reduce the MTU of the IPSec interface if large
packets of data are not being transmitted.
Create a tunnel to connect to the head office network
1
Click the
Add New Tunnel
tab.
2. Assign a name to the tunnel. The name must not contain spaces or start with a
number. For this example specify
Headquarters
.
3. Leave the
Enable this tunnel
checkbox checked.
4. Select the Internet port the IPSec tunnel is to go out on. The options will depend
on what is currently configured on the Shiva VPN Gateway. For the vast majority
of setups, this will be the default gateway interface to the Internet. For this
example, select the
default gateway interface
option.
Note:
You may want to select an interface other than the default gateway when
you have configured aliased Internet interfaces and require the IPSec tunnel to
run on an interface other than the default gateway.
Summary of Contents for SHIVA 1100
Page 38: ...QoS traffic shaping 38 System Administrator s Guide...
Page 44: ...DHCP relay 44 System Administrator s Guide...
Page 66: ...Access control 66 System Administrator s Guide...
Page 122: ...Technical Support 122 System Administrator s Guide...
Page 132: ...132 System Administrator s Guide...