Installation guide

Quadro Manual II: Administrator's Guide Administrator's Menus
Quadro4x, 4xi, 4xa, 4xia, 4xs, 4xis, Quadro16x, 16xi, 16xa, 16xia, 16xs, 16xis; (SW Version 3.1.x) 82
The first IPSec Connection Wizard page Add IPSec
Connection has the Connection Name text field that requires a
new IPSec connection name, which is mandatory, and should
be filled out, otherwise an error will occur: “Error: Incorrect
connection name”.
Please Note: The input in the Connection Name field should
be only in Latin characters, otherwise an error occurs and no
IPSec connection can be created.
The Peer type drop down list is used to choose the remote
machine type for the IPSec Connection to be established. If the
list does not include the required type of machine, choose
Other.
VPN Network Topology drop down list allows to select the
location of the peers participating to the VPN connection.
Following selections are present in the list:
Quadro<>Peer – direct connection between Quadro and a
peer.
Quadro<>[Internet]<>Peer – connection between Quadro
and peer over Internet.
Quadro<>NAT<>[Internet]<>Peer – connection between
Quadro and peer over Internet through Quadro provider’s
NAT.
Quadro<>[Internet]<>NAT<>Peer – connection between
Quadro and peer over Internet through peer provider’s
NAT.
Fig. II-130: IPSec Connection Wizard - Add IPSec Connection
The second page of the IPSec Connection Wizard, IPSec
Connection Properties serves to specify the members of the
IPSec Connection and to set the basic parameters for
encryption.
A group of radio buttons are used with Dynamic IP/Road
Warrior and Static IP/ Remote Gateway to select if the
remote Quadro (or another VPN gateway device) is
connected to the Internet with a dynamic IP address and is
acting as a Road Warrior, or is connected to the Internet with
a fixed IP address and is acting as a VPN Gateway.
If Dynamic IP / RoadWarrior is selected, the Remote
Gateway IP Address text field automatically will get the
value “any”, to allow access independent from the sending IP
address.
Selecting Static IP / Remote Gateway requires entering the
IP address or the hostname of the remote Quadro (or
another VPN gateway device) in the Remote Gateway text
field.
Please Note: Static IP/ Remote Gateway selection is not
possible if this Gateway is positioned behind NAT, since the
IP-address of the remote gateway is not reachable directly in
this case.
Quadro <> Remote Gateway allows access from the local
Quadro to the remote VPN gateway (local subnet and remote
subnet are not included). This includes management access.
Checkbox is disabled when
“Quadro<>NAT<>[Internet]<>Peer” or
“Quadro<>[Internet]<>NAT<>Peer” is selected from VPN
Network Topology drop down list on the first page of IPSec
Connection Wizard.
Local Subnet <> Remote Gateway allows access from all
stations connected to the local network to the remote VPN
gateway device (local Quadro and remote subnet are not
included). Checkbox is disabled when
“Quadro<>[Internet]<>NAT<>Peer” is selected from VPN
Network Topology drop down list on the first page of IPSec
Connection Wizard.
Fig. II-131: IPSec Connection Wizard -IPSec Connection Properties