Prestige 662HW Series User’s Guide
VPN Screens
16-11
Table 16-7 VPN IKE
LABEL DESCRIPTION
My IP Address
Enter the WAN IP address of your Prestige. The VPN tunnel has to be rebuilt if this IP
address changes.
The following applies if this field is configured as
0.0.0.0
:
The Prestige uses the current Prestige WAN IP address (static or dynamic) to set up
the VPN tunnel.
If the WAN connection goes down, the Prestige uses the dial backup IP address for the
VPN tunnel when using dial backup or the LAN IP address when using traffic redirect.
See the chapter on WAN for details on dial backup and traffic redirect.
Peer ID Type
Select
IP
to identify the remote IPSec router by its IP address.
Select
DNS
to identify the remote IPSec router by a domain name.
Select
to identify the remote IPSec router by an e-mail address.
Content The
configuration
of the peer content depends on the peer ID type.
For
IP
, type the IP address of the computer with which you will make the VPN
connection. If you configure this field to
0.0.0.0
or leave it blank, the Prestige will use
the address in the
Secure Gateway Address
field (refer to the
Secure Gateway
Address
field description).
For
DNS
or
, type a domain name or e-mail address by which to identify the
remote IPSec router. Use up to 31 ASCII characters including spaces, although trailing
spaces are truncated. The domain name or e-mail address is for identification purposes
only and can be any string.
It is recommended that you type an IP address other than
0.0.0.0
or use the
DNS
or
E-
ID type in the following situations:
When there is a NAT router between the two IPSec routers.
When you want the Prestige to distinguish between VPN connection requests that
come in from remote IPSec routers with dynamic WAN IP addresses.
Secure Gateway
Address
Type the WAN IP address or the URL (up to 31 characters) of the IPSec router with
which you're making the VPN connection. Set this field to
0.0.0.0
if the remote IPSec
router has a dynamic WAN IP address (the
Key Management
field must be set to
IKE
).
In order to have more than one active rule with the
Secure Gateway Address
field set
to
0.0.0.0
, the ranges of the local IP addresses cannot overlap between rules.
If you configure an active rule with
0.0.0.0
in the
Secure Gateway Address
field and
the LAN’s full IP address range as the local IP address, then you cannot configure any
other active rules with the
Secure Gateway Address
field set to
0.0.0.0
.
Security Protocol
VPN Protocol
Select
ESP
if you want to use ESP (Encapsulation Security Payload). The ESP
protocol (RFC 2406) provides encryption as well as some of the services offered by
AH
. If you select
ESP
here, you must select options from the
Encryption Algorithm
and
Authentication Algorithm
fields (described below).
Summary of Contents for Prestige 662HW Series
Page 26: ......
Page 28: ......
Page 36: ......
Page 54: ......
Page 56: ......
Page 64: ......
Page 84: ......
Page 100: ......
Page 116: ......
Page 128: ......
Page 150: ......
Page 154: ......
Page 162: ......
Page 168: ......
Page 194: ......
Page 196: ......
Page 200: ......
Page 208: ......
Page 214: ......
Page 216: ......
Page 230: ......
Page 242: ......
Page 244: ......
Page 252: ......
Page 258: ......
Page 262: ......
Page 266: ......
Page 272: ......
Page 286: ......
Page 290: ......
Page 310: ......
Page 328: ......
Page 352: ......
Page 358: ......
Page 362: ......
Page 374: ......
Page 376: ......
Page 394: ......
Page 398: ......
Page 400: ......
Page 410: ......
Page 444: ......
Page 452: ......