
AR3088 ROUTER USER MANUAL
Tel:+86 592-6195619
Fax:+86 592-6195620
Add:NO.146-148 XingBeiEr Road, JiMei District, XiaMen. China.
tunnel mode server
Local Subnet:
IPSec local protects subnet and subnet mask, i.e. 192.168.1.0/24; this option
can not fill in if using transfer mode.
Remote Subnet:
IPSec opposite end protects subnet and subnet mask, i.e.192.168.7.0/24;
this option can not fill in if using transfer mode.
Local ID:
tunnel local end identification, IP and domain name are available.
Remote ID:
tunnel opposite end identification, IP and domain name are available.
Use a Pre-Shared Key:
choose use share encryption option.
Enable Advanced Settings:
enable to configure 1
st
and 2
nd
phase information, otherwise it
will automic negotiation according to opposite end.
Phase 1(IKE)
Encryption:
IKE phased encryption mode.
Integrity:
IKE phased integrity solution.
DHGrouptype:
DH exchange algorithm.
Lifetime:
set IKE lifetime, current unit is hour, the default is 0.
Phase 2(ESP)
Encryption:
ESP encryption type.
Integrity:
ESP integrity solution.
Keylife:
set ESP keylife, current unit is hour, the default is 0.
IKE aggressive mode allowed:
negotiation mode adopt aggressive mode if tick; it is main
mode if non-tick.
Perfect Forward Secrecy:
Tick to enable PFS, non-tick to diable PFS.
Enable DPD Detection:
enable or disable this function, tick means enable.
Time Interval:
set time interval of connect detection (DPD).
Timeout:
set the timeout of connect detection.
Action:
set the action of connect detection.
3.6.4 GRE
GRE (Generic Routing Encapsulation, Generic Routing Encapsulation) protocol is a network
layer protocol (such as IP and IPX) data packets are encapsulated, so these encapsulated data
packets to another network layer protocol (IP)transmission. GRE Tunnel (tunnel) technology,
Layer Two Tunneling Protocol VPN (Virtual Private Network).