116
6620-3201
This eroute is tunnelled within another eroute:
It is now possible to tunnel packets within a second (or more) tunnel. When this parameter is set to
“On”, the unit will take outgoing packets going through this tunnel and once tunnelled, will recheck to
see if the resultant packet also goes through a tunnel.
If the inner tunnel is an IPsec tunnel (i.e. needs IKE), you can get the inner IKE to use the correct
source address (matching the outer tunnel selectors) by setting the
Use secondary IP address
parameter to “Yes” and the inner IKE will use the IP address set in the
Secondary IP address
parameter on the
Confi gure
>
General
page.
GRE mode:
This parameter enables GRE (Generic Routing Encapsulation) for this Eroute instance. GRE is a
simple tunnelling protocol that does not provide encryption or authentication. To use GRE it is not
necessary to con
fi
gure most of the parameters on this page. The following parameters only will need
to be con
fi
gured on this page:
♦
Peer IP/hostname
♦
Local subnet IP address
♦
Remote subnet IP address
♦
Remote subnet mask
♦
GRE
Additionally the GRE parameter will have to be enabled on the appropriate Interface, e.g. for PPP
1 on the
Confi gure
>
PPP
>
PPP 1
>
Standard
page this would be achieved by setting the
GRE
parameter to “Yes”. For further details refer to RFC2784.
NAT traversal keep-alive interval (s):
This parameter may be used to set a timer (in seconds), such that the unit will send regular packets to
a NAT device in order to prevent the NAT table from expiring.
Link Eroute with interface / Link Eroute with interface #:
These parameters can be con
fi
gured to ensure that the Eroute only match packets using the speci
fi
ed
interface.
IKE confi g to use when initiator:
This parameter is used to specify whether the IKE 0 or IKE 1 con
fi
g is used when the unit is being
con
fi
gured as an Initiator.
IKE version:
This parameter allows you to choose which version of IKE to use. The default value is “1”.
Check APN usage:
When this parameter is set to “Yes”, the Eroute can only use the APN speci
fi
ed in
the
Interface must use this APN
parameter.
Interface must use this APN:
This parameter allows you to choose between using the main APN or
the backup APN, as de
fi
ned in the
Confi gure
>
GPRS Module
page
Use Secondary IP address:
When this parameter is set to “ON”, tunnels set up from this eroute will use the IP address set in
the
Secondary IP address
parameter on the
Confi gure
>
General
page as the source address for
tunnelled packets. This gives the unit the ability to set two tunnels up to a single remote peer, and
appear as though it is two separate units. Use in conjunction with
This eroute is tunnelled within
another eroute
.
Delete SAs when eroute goes out of service:
When this parameter is set to “Yes”, and the Eroute goes out of service, any SA’s associated with the
Eroute will be deleted.