User's Manual
Table Of Contents
42
Dynamic NATT Port Click to enable dynamic NATT port Disable
3.6.2 IPSec Tunnels
From navigation tree, select VPN>>IPSec Tunnels, enter "IPSec Tunnels" and click <add>.
Table 3-6-2 Parameters of IPSec Tunnels
IPSec Tunnels
Function description: Configure IPSec tunnels
Parameters Description Default
Show Advanced Options Click to enable advanced options
Disable(open advanced
options after enabling)
Basic parameters
Tunnel Name User defines tunnel name IPSec_tunnel_1
Destination Address
Set destination IP address or domain
name
0. 0. 0. 0
Startup Modes
Select Auto Activated/Triggered by
Data/Passive/Manually Activated
Auto Activated
Restart WAN when failed Click to enable Enable
Negotiation Mode
Select main mode or aggressive
mode
Main Mode
IPSec Protocol (Advanced
Option)
Select ESP/AH ESP
IPSec Mode (Advanced
Option)
Select tunnel mode/transmission
mode
Tunnel Mode
VPN over IPSec (Advanced
Option)
Select L2TP over IPSec/GRE over
IPSec/None
None
Tunnel Type
Select
Host-Host/Host-Subnet/Subnet-Host/
Subnet-Subnet
Subnet-Subnet
Local subnet address Set local subnet IP address 192. 168. 2. 1
Local Subnet Mask Set local subnet mask 255. 255. 255. 0
Peer Subnet Address Set peer subnet IP address 0. 0. 0. 0
Peer Subnet Mask Set remote netmask 255. 255. 255. 0
Phase I Parameters
IKE Strategy Multiple strategies available 3DES-MD5-DH2
IKE Life Cycle Set IKE life cycle 86400 s
Local ID Type
Select IP address/User FQDN/FQDN
Fill in the ID according to the ID type
(USERFQDN is standard email
format)
IP Address
Peer ID Type Select IP address/User FQDN/FQDN IP Address
Authentication method Select shared key/digital certificate Shared key