Functions
MoRoS ADSL 2.1 PRO
In order to adjust the MRU (maximum permissible number of bytes in a
packet to be received), change the entry in the respective field.
The default settings of MTU and MRU are suitable for most
applications and do not need to be modified usually.
In order to configure a connection check using a ping via ICMP protocol
to a domain or an IP address, enter this into the entry field "Additional
ICMP ping to". It is recommended to enter a domain name or IP address,
which can only be connected via the tunnel, here. If the connection
check is not successful, a possibly existing tunnel will be terminated, and
a new tunnel will be established. The ping interval is 15 minutes.
If a tunnel aborts, this will not be re-established automatically, but the
establishment will only be made after a new WAN connection
establishment. Therefore, the condition of the tunnel should be
checked using an ICMP ping in any case.
In order to confirm all settings for the loaded tunnel made above, click
on "OK".
13.3.8
Setting Up IPsec
IPsec (Internet Protocol Security) is a security protocol for the safe communication
via IP networks and can be used to set-up virtual private networks (VPN). Two
subnets can be connected together using two suitable routers (e.g. INSYS
MoRoS 2.1) via a secure tunnel. It is possible to configure up to 10 different
tunnels.
Configuration via the web interface
In order to use the IPsec for a connection, check in the menu "LAN (ext)"
on the page "IPsec" the checkbox "Activate IPsec".
In order to display the current state of the IPsec tunnels, select the link
"IPsec current state".
In order to display the messages of the last connection, select the link
"Display log of last connection".
In order to configure NAT traversal, use the drop-down list "NAT-
Traversal" to select the desired option. If you select "activate" (default
setting), all ESP (Encapsulating Security Payload) packets are additionally
packed into a UDP packet and sent using the UDP port 4500, if a NAT
router is detected. If you select "force", this behaviour will be enforced
without checking for a NAT router (the remote terminal must also have
NAT traversal enabled in this case). If you select "deactivate", a UDP data
encapsulation will be prevented, what might lead to problems in
operation with a NAT router. This setting applies for all tunnels.
68