Twin WAN Series – User Guide | v1
Section 2: Global Settings (IKE)
Planning the VPN
Consider these questions and setup issues when planning your VPN:
•
If the remote end is a LAN network, the two-endpoint network must have
different LAN IP address ranges. If the remote endpoint is a single PC running a
VPN client, its destination address must be a single IP address, with subnet mask
of 255.255.255.255
•
Will you be using the Internet Key Exchange (IKE) setup or Manual Keying? For
either method, you must specify each phase of the connection.
•
At least one side must have a fixed IP address. The other side with a dynamic IP
address must always be the initiator of the connection.
•
What encryption level will you use? (DES/3DES - hardware encryption; AES -
software encryption)
IKE Global Setting
The XC-DPG503 and 603 are shipped to the customer with VPN features disabled by
default. To enable this feature, use the Global Setting page and check the Enable box on
WAN 1, WAN 2, or both WAN ports. Upon enabling these settings, you will need to
match the settings of the remote endpoint. All XiNCOM VPN gateways ship with the
same default Global Parameters. If you are connecting to another XiNCOM VPN
endpoint using the default values, you do not have to make any changes to this page.
Once the VPN feature is enabled, VPN Policies and Mesh Groups (DPG603 only) may
be created.
To connect to another VPN gateway or to create a policy so VPN clients can connect to
the gateway, please use the Policy Setup page. Policy Setup allows you to create a single
tunnel to connect to a remote VPN endpoint of any brand which supports the standard
IPsec protocol.
If the VPN Aggregation or VPN Failover is desired, use the Mesh Group setup page . The
Mesh Group allows you to create four different tunnels at once instead of using Policy
Setup. This feature is created to save time and avoid uncorrelated settings between
policies. The setting then may be fine tuned using the Policy Setup page. When the group
is created, you can use the Modify button to edit the settings or you can use the Policy
Setup to edit and fine tune each individual tunnel.
Copyright © 2005 WINS International, LLC dba XiNCOM | All rights reserved.
57