MoRoS GPRS 2.1 PRO
Functions
If a tunnel aborts, this will not be re-established automatically, but the
establishment will only be made after a new WAN connection estab-
lishment. Therefore, the condition of the tunnel should be checked us-
ing an ICMP ping in any case.
In order to confirm all settings for the loaded tunnel made above, click on
"OK".
12.6.8
Setting Up IPsec
IPsec (Internet Protocol Security) is a security protocol for the safe communication
via IP networks and can be used to set-up virtual private networks (VPN). Two sub-
nets can be connected together using two suitable routers (e.g. MoRoS GPRS 2.1
PRO) via a secure tunnel. It is possible to configure up to 10 different tunnels.
Configuration via the web interface
In order to use the IPsec for a connection, check in the menu "Dial-In",
"Dial-Out", or "LAN (ext)" on the page "IPsec" the checkbox "Activate IP-
sec".
In order to display the current state of the IPsec tunnels, select the link
"IPsec current state".
In order to display the messages of the last connection, select the link
"Display log of last connection".
In order to configure NAT traversal, use the drop-down list "NAT-
Traversal" to select the desired option. If you select "activate" (default set-
ting), all ESP packets are additionally packed into a UDP packet and sent
using the UDP port 4500, if a NAT router is detected. If you select "force",
this behaviour will be enforced without checking for a NAT router (the re-
mote terminal must also have NAT traversal enabled in this case). If you
select "deactivate", an UDP data encapsulation will be prevented, what
might lead to problems in operation with a NAT router. This setting ap-
plies for all tunnels.
In order to configure the interval of the keep alive packets, which are sent,
if NAT traversal is used, enter the time in seconds into the field "Keep
alive interval". This can prevent that e.g. a stateful firewall blocks the con-
nection after an extended inactivity period.
In order to select the tunnel, whose settings are to be edited, select the
desired tunnel from the drop-down list "Tunnel name" and click on the
button "load to edit" then. If settings are made to the currently loaded
tunnel, these must be taken over before using the button "OK", before a
new tunnel is loaded to prevent that these settings get lost. Loading a
tunnel does not save settings that have been made!
In order to activate the loaded tunnel, check the checkbox "Activate tun-
nel".
79
Summary of Contents for MoRoS GPRS 2.1 PRO
Page 1: ...Manual MoRoS GPRS 2 1 PRO...
Page 2: ......
Page 82: ...Functions MoRoS GPRS 2 1 PRO 82...
Page 144: ......