User guide
VPN Configuration
Rev 2.3 Feb.12 71
VPN 1
The VPN 1 tunnel can be configured as IPsec, GRE, SSL, or L2TP+IPsec.
Enabling any of these tunnels will expose other options for configuring the tunnel.
Figure 6-2: ACEmanager: VPN - VPN 1
IPsec
The IPsec architecture model includes the Sierra Wireless AirLink gateway as a
remote gateway at one end communicating, through a VPN tunnel, with a VPN
gateway at the other end. The remote gateway is connected to a Remote network
and the VPN is connected to the Local network. The communication of data is
secure through the IPsec protocols.
The IPsec VPN employs the IKE (Internet Key Exchange) protocol to set up a
Security Association (SA) between the AirLink device and a Cisco (or Cisco
compatible) enterprise VPN server. IPsec consists of two phases to setup an SA
between peer VPNs. Phase 1 creates a secure channel between the AirLink
Device VPN and the enterprise VPN, thereby enabling IKE exchanges. Phase 2
sets up the IPsec SA that is used to securely transmit enterprise data.