ACM VPN Configuration
Rev 3 Nov 17
41
4119855
iii.
In Device USB IP, enter the AirLink device’s IP address.
The default address is 192.168.14.31. If the gateway is part of a fleet,
each gateway must be configured with a unique address—modify the
third octet for each device (e.g. 192.168.
14
.31 for the first gateway,
192.168.
15
.31 for the second, etc.)
iv.
Click Apply.
·
Ethernet IP address:
i.
In ACEmanager, select LAN > Ethernet.
ii.
In Device IP, enter the AirLink device’s IP address.
The default address is 192.168.13.31. If the gateway is part of a fleet,
each gateway must be configured with a unique address—modify the
third octet for each device (e.g. 192.168.
13
.31 for the first gateway,
192.168.
14
.31 for the second, etc.)
iii.
Click Apply.
2.
Select VPN > [VPN#].
a.
In VPN 1 type, select IPsec Tunnel.
b.
In Local Address Type, select “Single Address” from the drop-down list.
c.
In Local Address, enter the IP address (USB or Ethernet) set in step 1.
d.
Click Apply.
e.
Click Reboot.
Main/Aggressive Mode Configuration
AirLink gateways/routers support IKEv1 in main mode and aggressive mode.
When determining whether to configure an AirLink device for aggressive mode,
consider the following use cases:
For each device configured to use aggressive mode, configure the ACM using:
set vpn ipsec site-to-site peer <PeerID> authentication
aggressivemode yes
(See
on page 27 for supported <PeerID> types and formats.)
Table 5-6: Main / Aggressive Mode Use Cases
Main Mode
Main Mode + FQDN
Aggressive Mode
•
Secure
•
Available only if ID Authen-
tication ID Type is Static IP
address
•
Secure
•
Best option if Static IP
address is not available.
•
All gateways/routers use the
same PSK—If PSK is
compromised, all gateways/
routers in fleet must be
configured with a new PSK.
•
Not secure, PSK transmitted
unencrypted in Phase 1.
•
Gateways can use different
PSKs
•
If user accepts the security risk,
this option allows for faster
setup.