Draytek Vigor3910 Series User Manual page 212

Multi-wan security router
Hide thumbs Also See for Vigor3910 Series:
Table of Contents

Advertisement

Item
Subnet
IKE Authentication
Method
202
Description
Name and Password of remote dial-in user below.
IPSec Tunnel - Allow the remote dial-in user to establish IPsec
tunnels.
L2TP with IPSec Policy - Allow the remote dial-in user to
establish L2TP VPN connections. You can select to use L2TP
alone or with IPSec. Select one of the following options:
None - Do not apply the IPSec policy. L2TP connections
are not encrypted.
Nice to Have - Attempt to establish an IPsec secure
channel first, before starting an L2TP session. If an IPsec
secure channel cannot be established with the remote
client, fall back to an L2TP connection without
encryption.
Must - Require that an IPsec secure channel be
established before starting an L2TP connection.
Disconnect if an IPsec secure channel cannot be
established.
SSL Tunnel - Select to allow the remote dial-in user to initiate
SSL VPN tunnels.
OpenVPN Tunnel - Select to allow the remote dial-in user to
initiate OpenVPN tunnels.
Specify Remote Node - Select this option to specify the
remote IP address, ISDN number or peer ID (used in IKE
aggressive mode) used to authenticate the remote dial-in
user. If this option is not selected, the authentication and
security methods specified in the general settings will be used
instead.
Netbios Naming Packet
Pass – Select this to allow Netbios name inquiries
between the hosts located on both sides of VPN Tunnel.
Block – Select this to block Netbios name inquiries
between remote and local hosts.
Multicast via VPN - Some programs might send multicast
packets via VPN connection.
Pass –Select this to allow multicast packets to pass
through VPN connections.
Block –Select this to block multicast packets from passing
through the VPN connections. This is the default setting.
Select a subnet for this VPN profile.
Assign Static IP Address –If you would like to assign a static IP
address to this user, enter it here.
All fields in this section, except for Digital Signature (X.509),
are applicable to IPsec Tunnels and L2TP connections with
IPsec Policy when you specify the IP address of the remote
node (Remote Client IP in Specify Remote Node above).
Digital Signature (X.509) can be used with IPSec tunnels
regardless of the IP address of the remote node is specified or
not.
Pre-Shared Key - Select this checkbox to enable Pre-shared
Key function and enter a string of up to 63 characters as the
pre-shared key.
Digital Signature (X.509) – Select this checkbox to enable
X.509 Digital Signature and choose a predefined profile that
Vigor3910 Series User's Guide

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents