Digi Connect WAN Series User Manual page 61

Hide thumbs Also See for Connect WAN Series:
Table of Contents

Advertisement

Digi Connect WAN Family web interface
connect directly to devices on the other private network with which the VPN tunnel is established. You
configure VPN tunnels using security settings and methods to ensure the networks are secured.
Use the Digi device for primary or backup remote site connectivity. The Digi device routes secured
IPsec VPN traffic over the cellular IP network and a VPN appliance terminates it at the host end.
You can use a VPN-enabled Digi device in several scenarios; for example:
As the primary router where the remote site does not use another WAN router.
n
As a backup router where the remote site has a primary WAN connection through DSL, Frame
n
Relay, or other means.
To provide secure access to remote serial and/or Ethernet devices.
n
This section describes using a Digi device as a primary remote site router using IPsec Encapsulated
Security Payload (ESP) and Internet Key Exchange (IKE)/Internet Security Association and Key
Management Protocol (ISAKMP) pre-shared key methods.
VPN global settings
General Security Settings
n
Enable Antireplay: Antireplay allows the IPsec tunnel receiver to detect and reject
l
packets that have been replayed. Set this field to match that at the remote VPN gateway.
The default is Enabled.
Important
Miscellaneous Settings
n
Suppress SA lifetime during IKE Phase 1: In most cases, clear this check box. Some VPN
l
equipment do not negotiate the ISAKMP Phase 1 lifetimes. Such equipment may refuse to
negotiate with the Digi device if it includes lifetime values in Phase 1 negotiation
messages. If the Digi device must communicate with such equipment, enable this option to
prevent the Phase 1 lifetimes from being included in the ISAKMP Phase 1 messages.
Suppress Delete Phase 1 SA Message For PFS: In most cases clear this check box. VPN
l
devices usually send a delete notification for any phase 2 SAs that are left over from
previous sessions when they start to negotiate quick mode. However, some devices do not
handle this notification correctly and will terminate the connection when they receive it. If
you have trouble connecting to the remote VPN device, select this check box to suppress
sending this message.
IP addresses of remote VPN peers may change on the fly (Dynamic DNS): Enable when
l
you are specifying the address of the remote VPN device with a DNS name, and that device
uses dynamic DNS because its public IP address can change. Selecting this check box will
cause the Digi device to poll the DNS server once a minute to see if the remote VPN
device's IP address has changed. The IPsec software will be restarted with the new IP
address if it does change. Selecting this check box increases network traffic since the unit
will be polling the DNS server once a minute.
Digi Connect WAN Family User Guide
Disable Antireplay if you use manual keyed tunnels.
Configuration through the web interface
61

Advertisement

Table of Contents
loading

Table of Contents