NETGEAR FVS124G Configuration Manual page 31

Hide thumbs Also See for FVS124G:
Table of Contents

Advertisement

IPsec PFS: The setting must match the Perfect Forward Secrecy (PFS) setting in VPN Tracker (Advanced > Phase 2 >
Perfect Forward Secrecy (PFS)). Turning on PFS provides additional security.
IPsec PFS Key Group: The PFS key group must match the PFS Diffie-Hellman (DH) group in VPN Tracker (Advanced >
Phase 2 > Perfect Forward Secrecy (PFS)).
Traffic Selector
Advanced Users
If you are not setting the remote part of the Traffic Selection to "Any" (for example, because you
have different VPN policies all used by clients connecting from dynamic IP addresses), it must match
exactly what is configured in VPN Tracker as the Local Address (or Local Network, if using a
Network to Network connection). Range type addresses are not supported in VPN Tracker.
AH Configuration
The Traffic Selection settings determine the endpoints of the VPN
tunnel.
‣ The local (=NETGEAR) side of the tunnel should be configured to
be a subnet matching the NETGEAR's LAN
(192.168.13.0/255.255.255.0 is the NETGEAR's LAN in our
example)
‣ The remote part should be set to "Any".
Enable Authentication: VPN Tracker uses Encapsulating Security
Payload (ESP) with authentication. Using Authentication Header
(AH) is not necessary and not supported. It should be turned off.
31

Advertisement

Table of Contents
loading

Table of Contents