ACM Installation and Operations Guide
Rev 3 Nov 17
40
4119855
‘Single Address’ Type for Host2LAN
Connection
Typically, AirLink gateways/routers are configured to use LAN2LAN VPN
connections, which allows the AirLink device and its client devices to access the
VPN tunnel.
However, if the AirLink device must be configured to use a Host2LAN VPN
connection (where only the AirLink device can access the tunnel), the device
must be configured to use the “Single Address” local address type, and the
address must match the device’s USB IP address or Ethernet IP address to
establish a tunnel to the ACM.
1.
Check and update (if necessary) the IP address that will be used:
·
USB IP address:
i.
In ACEmanager, select LAN > USB.
ii.
In USB Device Mode, make sure USBNET is selected.
DH Group
1
Y
Y
On the AirLink device:
•
Configure the device to use only DH2
or DH5.
On the ACM:
•
Configure the peer to use only DH2 or
DH5.
•
Make sure the dh-group is configured
in esp-group proposals
2
Y
Y
Y
Y
5
Y
Y
Y
Y
14
Y
Y
15
Y
Y
16
Y
Y
17
Y
Y
18
Y
Y
19
20
21
none
Y
Y
Table 5-5: Additional ACM / AirLink Setup Requirements
Feature
Support limitation
Setup Requirement
Certificates
AirLink devices do not
support certificates
On the ACM, configure the
peer to use PSK only.
DNS Load Balancing
AirLink devices do not
support load balancing
n/a
Table 5-4: AirLink IKE / ESP Parameter Support (Continued)
ACM 1.6
AirLink
Type
IKE
ESP
IKE
ESP
Setup Requirements