MP1800-10 3G Router User Manual
Maipu Confidential & Proprietary Information
Page 66 of 95
Enable
: The switch of enabling the IPSec tunnel. By default, it is disabled.
If ticking, it is enabled.
NAT Traversal
: To prevent the NAT gateway from affecting the IPSec
tunnel, it is recommended to enable the NAT traverse (the tunnel data can
traverse the NAT gateway).
Auto Up
: After completing and saving the tunnel configuration, the
system automatically negotiates the tunnel. If ticking, it is enabled.
DPD interval
: The interval of the security tunnel detecting the peer
status (description: With the DPD interval, IPSEC sends one DPD detection
packet to judge whether the tunnel peer exists. If the peer does not
respond, IPSEC initiates re-negotiation).
DPD Max Fail Times
: Set the maximum re-transmission times of the
security tunnel peer status detection.
Remote gateway
: The remote gateway address (usually, it is the remote
public IP address).
Local Interface
: Select the interface at the local used to set up the
tunnel with the remote.
Authentication Method
: You can select the pre-share key or digital
certificate. Usually, we select the pre-share key.
Center certificate name
: Select the certificate of the authentication
center (CA certificate). The certificate requires uploading the
corresponding certificate in the certificate uploading configuration item.
(The item depends on the authentication mode as digital certificate and
the local ID type as ASD1DN.)
Certificate content
: Select the digital certificate. The certificate requires
uploading the corresponding certificate in the certificate uploading
configuration item. (The item depends on the authentication mode as
digital certificate and the local ID type as ASD1DN.)
Certificate private key
: Select the corresponding private key of the
digital certificate. The certificate requires uploading the corresponding
certificate in the certificate uploading configuration item or being got from
the certificate application. (The item depends on the authentication mode
as digital certificate and the local ID type as ASD1DN.)
Exchange mode
: You can select the master mode and positive mode.
Usually, we select the master mode.
My Identifier
: You can select address, FQDN, USER_FQDN, and ASD1DN.
My ID value
: You can input the corresponding tag according to the
selected local ID. The inputting method depends on the local ID type.
When selecting IP address, input the local IP address; when selecting
FQDN or USER_FQDN, you can fill in the character string; when selecting
ASD1DN, the item does not exist. ASD1DN is used for the digital
certificate.