Prestige 662HW Series User’s Guide
16-4
VPN Screens
Table 16-2 VPN Summary
LABEL DESCRIPTION
No.
This is the VPN policy index number. Click a number to edit VPN policies.
Name
This field displays the identification name for this VPN policy.
Active
This field displays whether the VPN policy is active or not. A
Yes
signifies that this VPN policy
is active.
No
signifies that this VPN policy is not active.
Local Address
This is the IP address(es) of computer(s) on your local network behind your Prestige.
The same (static) IP address is displayed twice when the
Local Address Type
field in the
VPN-IKE
(or
VPN-Manual Key
) screen is configured to
Single
.
The beginning and ending (static) IP addresses, in a range of computers are displayed when
the
Local Address Type
field in the
VPN-IKE
(or
VPN-Manual Key
) screen is configured to
Range
.
A (static) IP address and a subnet mask are displayed when the
Local Address Type
field in
the
VPN-IKE
(or
VPN-Manual Key
) screen is configured to
Subnet
.
Remote Address This is the IP address(es) of computer(s) on the remote network behind the remote IPSec
router.
This field displays
N/A
when the
Secure Gateway Address
field displays
0.0.0.0
. In this case
only the remote IPSec router can initiate the VPN.
The same (static) IP address is displayed twice when the
Remote Address Type
field in the
VPN-IKE
(or
VPN-Manual Key
) screen is configured to
Single
.
The beginning and ending (static) IP addresses, in a range of computers are displayed when
the
Remote Address Type
field in the
VPN-IKE
(or
VPN-Manual Key
) screen is configured
to
Range
.
A (static) IP address and a subnet mask are displayed when the
Remote Address Type
field
in the
VPN-IKE
(or
VPN-Manual Key
) screen is configured to
Subnet
.
Encap.
This field displays
Tunnel
or
Transport
mode (
Tunnel
is the default selection).
IPSec Algorithm
This field displays the security protocols used for an SA.
Both
AH
and
ESP
increase Prestige processing requirements and communications latency
(delay).
Secure Gateway
IP
This is the static WAN IP address or URL of the remote IPSec router. This field displays
0.0.0.0
when you configure the
Secure Gateway Address
field in the
VPN-IKE
screen to
0.0.0.0.
Back
Click
Back
to return to the previous screen.
16.6 Keep Alive
When you initiate an IPSec tunnel with keep alive enabled, the Prestige automatically renegotiates the
tunnel when the IPSec SA lifetime period expires (see
for more on the IPSec SA
lifetime). In effect, the IPSec tunnel becomes an “always on” connection after you initiate it. Both
IPSec routers must have a Prestige-compatible keep alive feature enabled in order for this feature to
work.
If the Prestige has its maximum number of simultaneous IPSec tunnels connected to it and they all
have keep alive enabled, then no other tunnels can take a turn connecting to the Prestige because the
Prestige never drops the tunnels that are already connected. Check
section 1.2 Features of the Prestige
in chapter 1 to see how many simultaneous IPSec SAs your Prestige model can support.
Summary of Contents for Prestige 662HW Series
Page 26: ......
Page 28: ......
Page 36: ......
Page 54: ......
Page 56: ......
Page 64: ......
Page 84: ......
Page 100: ......
Page 116: ......
Page 128: ......
Page 150: ......
Page 154: ......
Page 162: ......
Page 168: ......
Page 194: ......
Page 196: ......
Page 200: ......
Page 208: ......
Page 214: ......
Page 216: ......
Page 230: ......
Page 242: ......
Page 244: ......
Page 252: ......
Page 258: ......
Page 262: ......
Page 266: ......
Page 272: ......
Page 286: ......
Page 290: ......
Page 310: ......
Page 328: ......
Page 352: ......
Page 358: ......
Page 362: ......
Page 374: ......
Page 376: ......
Page 394: ......
Page 398: ......
Page 400: ......
Page 410: ......
Page 444: ......
Page 452: ......