User guide

VPN SETUP
Enable: Check enable IPSec Proposal with this rule.
IPSec-Manual Setting
Tunnel name: Assign a name for this tunnel.
Method: There are IKE and Manual options. Choose Manual here.
Local subnet: The subnet of LAN site of local VPN gateway. It can be a host, a partial subnet, or the whole
subnet of LAN site of local gateway.
Local Netmask: The local netmask and associated local subnet can define a subnet domain for the devices
connected via the VPN tunnel.
Remote subnet: The subnet of LAN site of remote VPN gateway. It can be a host, a partial subnet, or the
whole subnet of LAN site of remote gateway.
Remote Netmask: The remote netmask and associated remote subnet can define a subnet domain for the
devices connected via the VPN tunnel.
Remote Gateway: Enter the IP address of remote VPN gateway.
Encapsulation Protocol: There are two protocols can be selected: ESP or AH.
Outbound SPI: SPI is an important parameter during hashing. Outbound SPI will be included in the
outbound packet transmitted from local gateway. The value of outbound SPI should be set in hex
formatted.
Inbound SPI: Inbound SPI will be included in the inbound packet transmitted from WAN site of remote
gateway. It will be used to de-hash the coming packet and check its integrity. The value of outbound SPI
should be set in hex formatted.
Encryption Algorithm: There are two algorithms can be selected: DES, or 3DES.
Encryption Key: Encryption key is used by the encryption algorithm. Its length is 8 bytes if encryption
algorithm is DES or 24 bytes if 3DES. The key value should be set in hex formatted.
Authentication Algorithm: There are two algorithms can be selected: SHA1 or MD5.
Authentication Key: Authentication key is used by the authentication algorithm. Its length is 16 bytes if
authentication algorithm is MD5 or 20 bytes if SHA1. Certainly, its length will be 0 if no authentication
algorithm is chosen. The key value should be set in hex formatted.
VPN-PPTP Server
The VPN gateway can behave as a PPTP server, and allows remote hosts to access LAN servers behind the PPTP
server. The device can support three authentication methods: PAP, CHAP, and MSCHAP(v1 and v2). Users can also
enable MPPE encryption when using MSCHAP.
VPN-PPTP Server: Enable or Disable PPTP server function.
Server Virtual IP: The IP address of PPTP server. This IP address should be different from IP address of L2TP
server and LAN subnet of VPN gateway.
IP Pool Start Address: This device will assign an IP address to remote PPTP client. This value indicates the
beginning of IP pool.
IP Pool End Address: This device will assign an IP address to remote PPTP client. This value indicates the end
of IP pool.
Authentication Protocol: Choose authentication protocol as PAP, CHAP, or MSCHAP(v1 or v2).
MultiConnect
®
rCell 500 Series Router User Guide 39