SETUP
Page 36
DOC_DEV_Router setup guide_A
That VPN IP address must not be confused with the WAN interface IP address.
Leave the default values 172.16.0.0 and 255.255.0.0
“Connection death time
-
out” parameter :
A control message (also called Keep-alive message) is sent periodically by the VPN server Router to make
sure that the VPN must be left active.
This parameter defines the period of the control messages.
As a consequence, it sets the maximum amount of time a VPN connection will stay established before being
cleared if no response to the VPN control message is received from the remote Router.
Remark :
The value of this parameter must be selected carefully; If the VPN has been cleared, for any reason, the
router will wait during that period of time before launching the VPN again.
“Packet retransmit time
-
out” parameter:
This parameter sets the amount of time (in seconds) the server will wait for the response to the keep-alive
control message before repeating it.
“Encryption algorithm” & “Authentication algorithm” parameter :
AES provides a better encryption than 3DES, and SHA-1 a better authentication than MD5.
« Priority » parameter :
Enter an intermediate value : 100 for instance.
« Push local route to VPN clients » parameter :
If that checkbox is selected, the server broadcasts to the clients the route to the IP domain of its local
network.
Leave that checkbox selected.
«Push static routes to VPN clients » parameter :
If that checkbox is selected, the server broadcasts to the clients the static routes which have been set-up in
the VPN server.
Leave that checkbox selected.
«Push client routes » checkbox :
Two solutions exist to enable a device connected to a VPN client Router to exchange data with another
device connected to another VPN client Router.
The first one is to program a static route in both VPN client Routers.
The second o
ne is to select the “Push clients routes” option.
•
If that option is selected, the VPN server broadcast to all the VPN clients the route to each of them.
In that way, each device of the network can exchange data with each other device.
Programming static routes is not necessary.
•
If that option is not selected, a device connected to a VPN client Router can exchange data with a device
connected to the LAN network of the VPN server, but not with a device connected to one other VPN client
Router.
If it is necessary static routes must be programmed in both routers.
« 1st specific route to push» & « 2nd specific route to push» parameters :
These parameters allow to broadcast specific routes from the VPN server to the clients.
Summary of Contents for RAS Series
Page 1: ...DOC_DEV_Router setup guide_A RAS IPL SIG _________________ SETUP GUIDE _________________ ...
Page 8: ......
Page 14: ......