Host Name - peplink ONE 20 User Manual

Multi-wan bonding routers
For more information, please visit peplink.com
Hide thumbs Also See for ONE 20:
Table of Contents

Advertisement

USER MANUAL
Peplink Balance Series
Gateway IP
Address /

Host Name

Local
Enter the local LAN subnets here. If you have defined static routes, they will be shown
Networks
here.
Remote
Enter the LAN and subnets that are located at the remote site here.
Networks
To access your VPN, clients will need to authenticate by your choice of methods. Choose
Authentication
between the Preshared Key and X.509 Certificatemethods of authentication.
Choose Main Mode if both IPsec peers use static IP addresses.Choose Aggressive
Mode
Mode if one of the IPsec peers uses dynamic IP addresses.
Force UDP
For forced UDP encapsulation regardless of NAT-traversal, tick this checkbox.
Encapsulation
Pre-shared
This defines the peer authentication pre-shared key used to authenticate this VPN
Key
connection. The connection will be up only if the pre-shared keys on each side match.
Remote
Certificate
Available only when X.509 Certificate is chosen as the Authentication method, this field
(pem
allows you to paste a valid X.509 certificate.
encoded)
InMain Mode, this field can be left blank. InAggressive Mode, if Remote Gateway IP
Local ID
Addressis filled on this end and the peer end, this field can be left blank. Otherwise, this
field is typically a U-FQDN.
InMain Mode, this field can be left blank.InAggressive Mode, if Remote Gateway IP
Remote ID
Addressis filled on this end and the peer end, this field can be left blank. Otherwise, this
field is typically a U-FQDN.
InMain Mode, this allows setting up to sixencryption standards, in descending order of
Phase 1 (IKE)
priority, to be used in initial connection key negotiations.InAggressive Mode, only one
Proposal
selection is permitted.
This is the Diffie-Hellman group used within IKE. This allows two parties to establish a
shared secret over an insecure communications channel. The larger the group number,
Phase 1 DH
the higher the security.
Group
Group 2:1024-bit is the default value.
Group 5:1536-bit is the alternative option.
Phase 1 SA
This setting specifies the lifetime limit of this Phase 1 Security Association. By default, it is
Lifetime
set at 3600 seconds.
InMain Mode, this allows setting up to sixencryption standards, in descending order of
Phase 2 (ESP)
priority, to be used for the IP data that is being transferred.InAggressive Mode, only one
Proposal
selection is permitted.
Phase 2 PFS
Perfect forward secrecy (PFS) ensures that if a key was compromised, the attacker will be
http://www.peplink.com
-117 / 258 -
Copyright © 2015 Peplink

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents