MLR 3G 2.0
Functions
The default settings of MTU and MRU are suitable for most applications
and do not need to be modified usually.
In order to
send a ping via ICMP protocol
to a domain or an IP address addi-
tionally, enter this into the entry field "Additional ICMP Ping to". It is recom-
mended to enter a domain name or IP address, which can only be connected
via the tunnel, here. If the ping is not successful, a possibly existing tunnel will
be terminated, and a new tunnel will be established. The ping interval is 15
minutes.
If a tunnel aborts, this will not be re-established automatically, but the es-
tablishment will only be made after a new WAN connection establishment.
Therefore, the condition of the tunnel should be checked using an ICMP
ping in any case.
In order to
confirm all settings for the loaded tunnel
made above, click on
"OK".
10.5.8
IPsec
IPsec (Internet Protocol Security) is a security protocol for the safe communication via IP
networks and can be used to set-up virtual private networks (VPN). Two subnets can be
connected together using two suitable routers (e.g. MoRoS 2.1) via a secure tunnel. It is
possible to configure up to 10 different tunnels.
Configuration with the web interface
In order to use
the IPsec for a connection
, check in the menu "Dial-In" or "Dial-
Out" on the page "IPsec" the checkbox "Activate IPsec".
In order to
display the current state of the IPsec tunnels
, select the link "IPsec
current state".
In order to
display the messages of the last connection
, select the link "Display
log of last connection".
In order to
configure NAT traversal
, use the drop-down list "NAT-Traversal" to
select the desired option. If you select "activate" (default setting), all ESP pack-
ets are additionally packed into a UDP packet and sent using the UDP port
4500, if a NAT router is detected. If you select "force", this behaviour will be
enforced without checking for a NAT router (the remote terminal must also
have NAT traversal enabled in this case). If you select "deactivate", an UDP
data encapsulation will be prevented, what might lead to problems in opera-
tion with a NAT router. This setting applies for all tunnels.
In order to
configure the interval of the keep alive packets
, which are sent, if
NAT traversal is used, enter the time in seconds into the field "Keep alive in-
terval". This can prevent that e.g. a stateful firewall blocks the connection af-
ter an extended inactivity period.
57