Available settings are explained as follows:
Item
Enabled
Certificate
Preferred Local ID
General Site-to-Site
PSK
XAuth User PSK
Mode
Accept VPN
Connections on
Description
Switch the toggle to enable/disable the settings.
Authentication Settings for Dynamic Peer
It usually applies to those teleworkers or VPN sites that use dynamic
IP addresses and IPsec-related VPN connections. There are two
methods to authenticate IPsec connections - Certificate (X.509) and
Pre-Shared Key(PSK).
To set up certificates on the router, go to the
Configuration>>Certificates section.
Select Alternative Subject Name or Subject Name.
Specify the preferred local ID information (Alternative Subject Name
First or Subject Name) for IPsec authentication.
Pre-Shared key - Define the PSK key for general authentication.
Pre-Shared Key - Define the PSK key for IPsec XAuth authentication.
More settings –
Maximum TCP segment size (VPN MSS)
Set the maximum segment size (MSS) for different VPN types.
Auto Adjustment by WAN MTU – VPN MSS is the maximum data size
that can be sent in a single TCP packet. It should be set to a value
lower than the network's MTU to prevent fragmentation.
Manually - Please specify the MSS values for each type to avoid
packets cut by MTU during the data transmission period via the IPsec
VPN connection.
IPsec
WireGuard
OpenVPN
Listen on Interface
Select the WAN interfaces to accept IPsec VPN connections.
All Interfaces – Accept the VPN connections on all WAN interfaces.
204
Need help?
Do you have a question about the Vigor2136 Series and is the answer not in the manual?