
User Interface
R&S
®
GP-U/GP-E/GP-S/GP-T
108
User Manual 3646.3836.02 ─ 01
Field
Description
"ON"/"OFF"
A slider switch indicates whether the IPsec connection is active ("ON") or inac-
tive ("OFF"). By clicking the slider switch, you can toggle the state of the con-
nection. A new connection is enabled by default.
"Name"
Enter a unique name for the connection. It must consist of 1 to 63 alphanumeric
characters and underscores.
"Connection type"
Select the type of the connection by clicking the respective radio button.
You can choose from the following three types:
●
"gateprotect VPN client" – A C2S connection with the gateprotect VPN cli-
ent is established.
The easily configurable gateprotect VPN client can be used for Client-to-
Site connections via the IPsec protocol.
●
"Client-to-Site" – A C2S connection with a standard VPN client is estab-
lished (e.g. for full tunneling).
●
"Site-to-Site" – A S2S connection is established.
"Network Connection"
From the drop-down list, select the network connection to be used to establish
the tunnel.
The elements on the "Network" tab depend on the selected connection type:
Field
Description
"Local network"
Enter the IP address of the local network that is reachable from the outside
through the VPN tunnel. It has to be in valid CIDR notation (IP address followed
by a slash »/« and the number of bits set in the subnet mask, for example
192.168.1.0/24
).
Note:
For full tunneling, enter
0.0.0.0/0
.
"Client IP"
Optional and for gateprotect VPN client and Client-to-Site connections only:
Enter the IP address under which the client is reachable.
"Use L2TP"
Optional and for Client-to-Site connections only: This checkbox is cleared by
default. You can select the checkbox if you want to establish the IPsec connec-
tion on Layer 2. In this case, the "Local network" is set to
0.0.0.0/0
.
"Remote network"
For Site-to-Site connections: Enter the IP address of the remote network that is
reachable through the VPN tunnel. It has to be in valid CIDR notation (IP
address followed by a slash »/« and the number of bits set in the subnet mask,
for example
192.168.1.0/24
).
"Destination"
For Site-to-Site connections: Enter the public IP address or hostname of the
IPsec server.
"Dynamic destination"
For Site-to-Site connections: This checkbox is cleared by default. If it is
selected, incoming connections from any remote end are allowed for this con-
nection. In this case, the "Destination" field is grayed out and it is not possible
to initiate the connection from the local side.
"Establish connection"
For Site-to-Site connections: Select whether the tunnel is established by the
local or by the remote site by selecting the respective radio button.
On the "Authentication" tab, you can define the authentication settings for the IPsec
connection:
Menu Reference