___________________________________________________________________________________
___________________________________________________________________________________
40 RG-5400 Subscriber router
–
Enable
– enable IPSec protocol utilization for data encryption;
–
Interface
– this setting takes effect only when PPPoE, PPTP or L2TP are selected for the Internet,
and defines the interface that will be accessed with IPSec: Ethernet (secondary access interface)
or PPP (primary access interface). When DHCP or Static protocol is selected, there is only a single
interface (Ethernet) active for the service that may be accessed with IPSec only.
–
Local IP address
– device address for operation via IPSec;
–
Local subnet address
in cooperation with
Local subnet mask
determine local subnet to create
network-to-network or network-to-point topology;
–
Remote subnet address
in cooperation with
Remote subnet mask
define a remote subnet
address used for IPSec-encrypted communication. If the mask value is 255.255.255.255,
communication is performed with a single host. Mask that differs from 255.255.255.255 allows
you to define a whole subnet. Thus, device features allow you to establish 4 network topologies
that utilize IPSec traffic encryption: Point-to-Point, Network-to-Point, Point-to-Network,
Network-to-Network;
–
Remote gateway
– gateway for access to remote subnet;
–
NAT-T mode –
NAT-T mode selection. NAT-T (NAT Traversal) encapsulates IPSec traffic and
simultaneously creates UDP packets to be sent correctly by a NAT device. For this purpose, NAT-
T adds an additional UDP header before IPSec packet so it would be processed as an ordinary
UDP packet and the recipient host would not perform any integrity checks. When the packet