
AG 5500
System Administration
95
Tunnel Peer Address
z
Select a Peer IP Address from the pull-down menu with which this security
association is to be established.
z
Must select a Peer if the policy is using ESP or AH.
z
Able to select ‘none’ only if policy is a discard or bypass policy
Traffic Selector
z
Protocol
z
To select a specific protocol via pull-down menu or protocol number
z
Protocol numbers available at
www.iana.org/assignments/protocol-numbers
The following settings define selectors of the Security Policy. All selectors must match in
order for the policy to be applied.
z
Remote End
z
Remote End/ Peer IP setting - The IP address of the remote VPN server.
z
Remote IP/Subnet - This is the IP address of the remote network secured by the
IPSec tunnel. The address could specify a host.
z
Subnet Mask - This is the subnet mask of the remote network secured by the
IPSec tunnel.
z
Remote Port – 0 is for all ports (only if protocol is UDP or TCP)
z
Local End
z
Choice of using current Network Interface IP address or specifying a subnet -
Security Policy can derive the settings for the Local End from the current
Network IP settings of the unit.
z
Local IP subnet - This is the IP address of the local network secured by the
IPSec tunnel. The address could specify a host.
z
Subnet Mask - This is the subnet mask of the local network secured by the
IPSec tunnel. The address could specify a host.
z
Local Port – 0 is for all ports (only if protocol is UDP or TCP)
z
IP address of network interface for this policy - This configuration is the IP
Address for the NSE inside an IPSec tunnel. The IP address must be within the
Local LAN subnet or the same as the Local LAN IP address. IP address 0.0.0.0
disables the functionality. The default setting is 0.0.0.0.
ag5500_userguide.book Page 95 Tuesday, June 5, 2007 7:31 PM
Summary of Contents for AG 5500
Page 1: ......
Page 6: ...This page intentionally left blank AG 5500 vi...
Page 40: ...This page intentionally left blank AG 5500 28 Introduction...
Page 46: ...AG 5500 34 Installing the AG 5500...
Page 68: ...This page intentionally left blank AG 5500 56 Installing the AG 5500...
Page 73: ...AG 5500 System Administration 61...
Page 106: ...AG 5500 94 System Administration IPSec Tunnel Security Policies...
Page 110: ...AG 5500 98 System Administration...
Page 115: ...AG 5500 System Administration 103...
Page 126: ...AG 5500 114 System Administration...
Page 174: ...AG 5500 162 System Administration...
Page 203: ...AG 5500 System Administration 191 The Internal Billing Options Setup screen appears...
Page 205: ...AG 5500 System Administration 193 Sample of Internal Billing Options XoverY Plan Setup Screen...
Page 210: ...AG 5500 198 System Administration...
Page 231: ...AG 5500 System Administration 219 4 Repeat Steps 1 3 for page 2 of 2 see following screen...
Page 234: ...AG 5500 222 System Administration 5 Repeat Steps 1 3 for page 3 of 3 see following screen...
Page 268: ...This page intentionally left blank AG 5500 256 The Subscriber Interface...
Page 299: ...AG 5500 Quick Reference Guide 287 Here is the output of cakey pem...
Page 301: ...AG 5500 Quick Reference Guide 289 Here is the output of server csr...
Page 316: ...This page intentionally left blank AG 5500 304 Troubleshooting...
Page 318: ...This page intentionally left blank AG 5500 306 Appendix A Technical Support...
Page 338: ...This page intentionally left blank AG 5500 326 Index...