Vanguard 3000 Multicarrier Cellular Data Modem & IP Router PN 134732-VG3000 Rev. D| Page 53
Figure 39: Security — IPsec
IPSec Configuration
IPsec
All IPsec functionality can be Enabled/Disabled with this control.
Drop Filters
This setting controls how packets for the Remote Subnet(s) are handled when an enabled tunnel is down.
When Enabled, packets that would normally go through the tunnel are discarded when the tunnel is down.
When Disabled, packets are routed through the appropriate interface. Their source address may be rewritten
by NAT but the destination address is unchanged. Most carriers will discard packets with “private IP” (e.g.
192.168.x.x) destination addresses but some carriers may quietly block any further traffic over the cellular
connection.
Tunnel Configuration
The Local and Remote Subnets are used to select the IP packets that are encrypted and sent in the tunnel. The Source
IP address is compared against the Local Subnet and the Destination IP address is compared against the Remote
Subnet(s).
Name
A name for the IPsec tunnel. Once a tunnel is defined, it can be enabled by checking the Enable box. To edit