
Operation and Configuration Guide 3.14
40
4118618
4.
Configure the VPN fields in accordance with the settings on the VPN server
being used. See
on page 85 for detailed infor-
mation on each setting.
5.
Click Save to save the VPN.
Tip:
When first testing a VPN, it's recommended that monitors be disabled initially in order
to test that all of the other configuration parameters are working properly.
Note: IPSec VPN has a maximum throughput of 40 Mbps due to the processing required
for encapsulation.
7.1 Detecting Dead VPN Connections
An oMG VPN profile can be configured to send packets to a VPN server in an
effort to detect dead connections. Doing so helps to protect resources by
attempting to reconnect to a VPN server.
When using IKEv1 for a VPN, Dead Peer Detection (DPD) can be enabled on the
VPN configuration screen which will detect when a VPN service is down.
For IKEv2, it is recommended that MOBIKE be enabled if multiple WAN links are
available which will automatically switch links when one goes down. MOBIKE has
been tested by Sierra Wireless against Sierra Wireless’ ACM VPN server. For
more information on compatibility with VPN servers contact Sierra Wireless
Technical Support (see
Important:
When MOBIKE is enabled, DPD should be disabled on the gateway side
because it can interfere with the fast switching provided by MOBIKE.
For both IKEv1 and IKEv2, it is recommended that a monitor be configured as
follows to detect a dead connection to the VPN server and to attempt to reconnect
to it.
•
The monitor's Host field must be set to a host which can only be reached
through the VPN.
•
The Source Address field must be set to a LAN segment assigned to the
VPN.
•
The monitor must then be assigned to the VPN profile by selecting it under
the Monitors field in the profile.
For information on creating a monitor see