Installation and Configuration Guidance
IP ROUTERS INSTALLATION GUIDE 3G OTU
667/CI/45025/000 Rev 4 Unrestricted
17
4
Once created, select
Edit
beside the newly created instance.
5
On the new page you will be required to enter the information as follows;
Setting
Value
Enable
Tick this box to enable the tunnel
Exchange mode
IKEv1-Aggressive
or
IKEv1-Main
Operation Level
Main
Authentication Meth-
od
Client
Remote VPN endpoint
Change to
'custom'
then enter the
public IP address for the VPNC
Local endpoint
Any
Local IKE identifier
[SCN]@[customer].com
(must match VPNC)
Remote IKE identifier
Instation_[SCN]@[customer].com
(must match VPNC)
Preshared Keys
Preshared key for this tunnel (refer to the ipsec.secrets file on VPNC)
Perfect Forward Secre-
cy
Enable
DPD action
Clear
DPD delay
30
seconds
(must match VPNC)
DPD timeout
120
seconds
(must match VPNC)
NAT traversal
Enable
Local LAN bypass
Tick this box if the local network range is contained within the remote range
Local subnet
Internal IP Address and subnet Mask (including any static routes) of the out-
station
Remote subnet
Internal IP Address and subnet Mask of cloud-hosted environment
Phase 1
Encryption algorithm
This is the AES value e.g. AES 256
(must match VPNC)
Hash algorithm
This is the 3DES/SHA value e.g.
HMAC_SHA1
(must match VPNC)
DH group
Set the Diffie Hellman Group e.g. MODP4096/16
(must match VPNC)
Life time
28800
(refer to lifetime details within ipsec.conf on VPNC)
Phase 2
Encryption algorithm
This is the AES value e.g. AES 256
(must match VPNC)
PFS group
Set the Diffie Hellman Group e.g. MODP4096/16
(must match VPNC)
Authentication
This is the 3DES/SHA value e.g.
HMAC_SHA1
(must match VPNC)
Life time
3600
(refer to lifetime details within ipsec.conf on VPNC)
Table 3 : IPSec Settings Table