User's Manual

Pepwave MAX and Surf User Manual
http://www.pepwave.com
80
Copyright @ 2015 Pepwave
13 IPsec VPN
IPsec VPN functionality securely connects one or more branch offices to your
company's main headquarters or to other branches. Data, voice, and video
communications between these locations are kept safe and confidential across the
public Internet.
IPsecVPN on Pepwave routersis specially designed for multi-WAN environments. For
instance, if a user sets up multiple IPsec profiles for a multi-WAN environment and
WAN1 is connected and healthy, IPsec traffic will go through this link. However, should
unforeseen problems (e.g.,unplugged cables or ISP problems) cause WAN1 to go down,
our IPsec implementation will make use of WAN2 and WAN3 for failover.
13.1 IPsec VPN Settings
ManyPepwaveproducts can makemultiple IPsec VPN connections with Peplink,
Pepwave, Cisco,andJuniper routers.Note that all LAN subnets and the subnets behind
them must be unique. Otherwise, VPN members will not be able to access each
other.All data can be routed over the VPN with a selection of encryption standards, such
as 3DES, AES-128, and AES-256.To configure IPsec VPN on Pepwave devices that
support it, navigate to Advanced>IPsec VPN.
A NAT-Traversal option and list of definedIPsec VPNprofiles will be shown. NAT-
Traversalshould be enabled if your system is behind a NAT router.Click the New
Profile button to create new IPsec VPN profiles that make VPN connections to remote
Pepwave, Cisco, or Juniper routers via available WAN connections. To edit any of the
profiles, click on its associated connection name in the leftmost column.