86
Set IPsec Remote Host, use the default setting if remote is dynamic IP
Remote Subnet
Set IPsec Remote Protected Subnet/Subnet Netmask
Click
Submit
to apply the configuration
.
An Example of IPSec VPN:
The reference topology above is how the branch office can get the access to the headquarter. The two laptops
are connected to the secure router switch through the Ethernet cable.
Enable the IPSec, type the same pre-share key and select the same cipher for both ends.
Configure the IP address for both ends. The Router at the branch office normally acts as the VPN Client role
(not really client mode in IPSec), the Router at head quarter normally acts as the VPN Server role. The HQ normally
has public IP, that’s the Remote IP of the router in branch office. The local subnet in HQ is the remote subnet of the
router in branch office. If you have public IP in branch, it’s better to use public IP address for the WAN interface. If
you just have dynamic IP address for branch office, then use 0.0.0.0 as local IP.
To check the connection status, you can use Ping tool in Router’s Web GUI to check the WAN connection. You
must ping remote WAN IP address successfully first. Then you can try ping from PC2 to its connected interface, WAN
IP of two routers and then remote PC1. This is also the typical debugging rule to check WAN and VPN connectivity.