Draytek VIGOR2950 User Manual page 111

Security vpn router
Hide thumbs Also See for VIGOR2950:
Table of Contents

Advertisement

GRE over IPSec Settings
TCP/IP Network Settings
Vigor2950 Series User's Guide
automatically. Please specify the time budget for the dial-in
user. The budget will be decreased automatically per callback
connection. The default value 0 means no limitation of
callback period.
Enable IPSec Dial-Out function GRE over IPSec: Check
this box to verify data and transmit data in encryption with
GRE over IPSec packet after configuring IPSec Dial-Out
setting. Both ends must match for each other by setting same
virtual IP address for communication.
Logical Traffic: Such technique comes from RFC2890.
Define logical traffic for data transmission between both sides
of VPN tunnel by using the characteristic of GRE. Even
hacker can decipher IPSec encryption, he/she still cannot ask
LAN site to do data transmission with any information. Such
function can ensure the data transmitted on VPN tunnel is
really sent out from both sides. This is an optional function.
However, if one side wants to use it, the peer must enable it,
too.
My GRE IP: Type the virtual IP for router itself for verified
by peer.
Peer GRE IP: Type the virtual IP of peer host for verified by
router.
My WAN IP - This field is only applicable when you select
ISDN, PPTP or L2TP with or without IPSec policy above.
The default value is 0.0.0.0, which means the Vigor router
will get a PPP IP address from the remote router during the
IPCP negotiation phase. If the PPP IP address is fixed by
remote side, specify the fixed IP address here. Do not change
the default value if you do not select ISDN, PPTP or L2TP.
Remote Gateway IP - This field is only applicable when you
select ISDN, PPTP or L2TP with or without IPSec policy
above. The default value is 0.0.0.0, which means the Vigor
router will get a remote Gateway PPP IP address from the
remote router during the IPCP negotiation phase. If the PPP IP
address is fixed by remote side, specify the fixed IP address
here. Do not change the default value if you do not select
ISDN, PPTP or L2TP.
Remote Network IP/ Remote Network Mask - Add a static
route to direct all traffic destined to this Remote Network IP
Address/Remote Network Mask through the VPN connection.
For IPSec, this is the destination clients IDs of phase 2 quick
mode.
More - Add a static route to direct all traffic destined to more
Remote Network IP Addresses/ Remote Network Mask
through the VPN connection. This is usually used when you
find there are several subnets behind the remote VPN router.
103

Advertisement

Table of Contents
loading

Table of Contents