Draytek Vigor2860 User Manual page 367

Vigor2860 series. vdsl2 security firewall
Hide thumbs Also See for Vigor2860:
Table of Contents

Advertisement

GRE over IPsec
Settings
Vigor2860 Series User's Guide
Specify Remote VPN Gateway - You can specify the IP
address of the remote dial-in user or peer ID (should be the
same with the ID setting in dial-in type) by checking the box.
Also, you should further specify the corresponding security
methods on the right side.
If you uncheck the checkbox, the connection type you select
above will apply the authentication methods and security
methods in the general settings.
Username - This field is applicable when you select PPTP or
L2TP with or without IPsec policy above. The length of the
name is limited to 11 characters.
Password - This field is applicable when you select PPTP or
L2TP with or without IPsec policy above. The length of the
password is limited to 11 characters.
VJ Compression - VJ Compression is used for TCP/IP
protocol header compression. This field is applicable when
you select PPTP or L2TP with or without IPsec policy above.
IKE Authentication Method - This group of fields is
applicable for IPsec Tunnels and L2TP with IPsec Policy when
you specify the IP address of the remote node. The only
exception is Digital Signature (X.509) can be set when you
select IPsec tunnel either with or without specify the IP
address of the remote node.
Pre-Shared Key - Check the box of Pre-Shared Key to
invoke this function and type in the required characters
(1-63) as the pre-shared key.
Digital Signature (X.509) –Check the box of Digital
Signature to invoke this function and select one
predefined Profiles set in the VPN and Remote Access
>>IPsec Peer Identity.
Local ID – Specify which one will be inspected
first.
Alternative Subject Name First – The alternative
subject name (configured in Certificate
Management>>Local Certificate) will be
inspected first.
Subject Name First – The subject name
(configured in Certificate Management>>Local
Certificate) will be inspected first.
IPsec Security Method - This group of fields is a must for
IPsec Tunnels and L2TP with IPsec Policy when you specify
the remote node.
Medium- Authentication Header (AH) means data will
be authenticated, but not be encrypted. By default,
this option is active.
High- Encapsulating Security Payload (ESP) means
payload (data) will be encrypted and authenticated.
You may select encryption algorithm from Data
Encryption Standard (DES), Triple DES (3DES), and AES.
Enable IPsec Dial-Out function GRE over IPsec: Check this
box to verify data and transmit data in encryption with GRE
over IPsec packet after configuring IPsec Dial-Out setting.
Both ends must match for each other by setting same virtual
IP address for communication.
Logical Traffic: Such technique comes from RFC2890. Define
logical traffic for data transmission between both sides of
353

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents