User's Manual
The following table describes each of the fields of the IPSec VPN Connection Settings page.
ITEM DEFINITION
IPSec Profile Enables or disables the VPN profile.
Profile Name A name used to identify the VPN connection profile.
Remote IPSec Server Address The IP address of the IPSec server.
Remote LAN Address Enter the IP address of the remote network for use on the VPN connection.
Remote LAN Subnet Mask Enter the subnet mask in use on the remote network.
Local LAN Address Enter the IP address of the local network for use on the VPN connection.
Local LAN Subnet Mask Enter the subnet mask in use on the local network.
Encapsulation Type
Select the encapsulation protocol to use with the VPN connection. You can choose ESP, AH or Any.
IKE Mode
Select the IKE mode to use with the VPN connection. You can choose Main, Aggressive or Any.
PFS Choose whether Perfect Forward Secrecy is ON or OFF for the VPN connection.
IKE Encryption Select the cipher type to use for the Internet Key Exchange.
IKE Hash
Select the IKE Hash type to use for the VPN connection. The hash is used for authentication of packets for the key
exchange.
IPSec Encryption Select the IPSec encryption type to use with the VPN connection.
IPSec Hash
Select the IPSec hash type to use for the VPN connection. The hash is used for authentication of packets for the
VPN connection.
DH Group
Select the desired Diffie-Hellman group to use. Higher groups are more secure but also require longer to generate a
key.
DPD Action
Select the desired Dead Peer Detection action. This is the action to take when a dead Internet Key Exchange Peer is
detected.
DPD Keep Alive Time Enter the time in seconds for the interval between Dead Peer Detection keep alive messages.
DPD Timeout Enter the time in seconds of no response from a peer before Dead Peer Detection times out.
IKE Rekey Time Enter the time in seconds between changes of the encryption key. To disable changing the key, set this to 0.
SA Life Time Enter the time in seconds for the security association lifetime.
Key Mode
Select the type of key mode in use for the VPN connection. You can select from:
• Pre Shared Key
• RSA keys
• Certificates
Pre-shared Key The pre-shared key is the key that peers used to authenticate each other for Internet Key Exchange.
Remote ID Specifies the domain name of the remote network.
Local ID Specifies the domain name of the local network.
Update Time Displays the last time the key was updated.
Local RSA Key Upload
Select the RSA key file for the local router here by clicking the Browse button.
Remote RSA Key Upload
Select the RSA key file for the remote router here by clicking the Browse button.
Private key Passphrase
The Private key passphrase of the router is the passphrase used when generating the router’s private key using
OpenSSL CA.
Key / Certificate
Select the type of key or certificate to use for authentication. You can select Local private key, Local public
certificate, Remote public certificate, CA certificate, CRL certificate.
IPSec Certificate Upload
Select the IPSec certificate to upload by clicking the Browse button.
Table 14 - IPSec Configuration Items
www.netcommwireless.com
NetComm Wireless CDMA M2M Router
45