Authentication algorithm:
The IKE authentication method (MD5, SHA1, SHA256, SHA384,
SHA512)
SA life time:
The Security Association lifetime in seconds
Perfect forward secrecy (PFS)
Specifies whether Perfect Forward Secrecy (PFS) should be used.
This feature increases security as PFS avoids penetration of the
key-exchange protocol and prevents compromization of previous
keys.
Force encapsulation:
Force UDP encapsulation for ESP packets even if no NAT situation
is detected.
Networks
When creating Security Associations, IPsec keeps track of routed networks within the tunnel. Packets
are only transmitted when a valid SA with the matching source and destination network is present.
Therefore, you may need to specify the networks behind the endpoints by applying the following settings:
Local network address:
The address of your Local Area Network (LAN)
Local network mask:
The netmask of your LAN
Peer network address:
The address of the remote network behind the peer
Peer network mask:
The netmask of the remote network behind the peer
NAT address:
Optionally, you can apply NAT (masquerading) for packets coming
from a different local network. The NAT address must reside in the
network previously specified as the local network.
Note
Since the firmware 3.7.40.103, the maximum number of networks for individual IPsec tunnels
has increased from 4 to 10.
M!DGE2 GPRS/UMTS/HSPA+/LTE router – © RACOM s.r.o.
98
Web Configuration
Summary of Contents for M!DGE2
Page 2: ......
Page 188: ...188 ...