Cisco RV042 Administration Guide - Page 133

E-mail Addr.USER FQDN Authentication, IP Address by DNS Resolved

Page 133 highlights

VPN Setting Up a Gateway to Gateway (Site to Site) VPN 9 - Dynamic IP + E-mail Addr.(USER FQDN) Authentication: Choose this option if this router has a dynamic IP address and does not have a Dynamic DNS hostname. Enter any Email Address to use for authentication. If both routers have dynamic IP addresses (as with PPPoE connections), do not choose Dynamic IP + Email Addr. for both gateways. For the remote gateway, choose IP Address and IP Address by DNS Resolved. • Local/Remote Security Group Type: Specify the LAN resources that can use this tunnel. The Local Security Group is for this router's LAN resources; the Remote Security Group is for the other router's LAN resources. - IP Address: Choose this option to specify one device that can use this tunnel. Then enter the IP address of the device. - Subnet: Choose this option (the default option) to allow all devices on a subnet to use the VPN tunnel. Then enter the subnetwork IP address and mask. - IP Range: Choose this option to specify a range of devices that can use the VPN tunnel. Then identify the range of IP addresses by entering the first address in the Begin IP field and the final address in the End IP field. IPSec Setup Enter the Internet Protocol Security settings for this tunnel. IMPORTANT: In order for any encryption to occur, the two ends of a VPN tunnel must agree on the methods of encryption, decryption, and authentication. Enter exactly the same settings on both routers. • Keying Mode: Choose one of the following key management methods: - Manual: Choose this option if you want to generate the key yourself and you do not want to enable key negotiation. Manual key management is used in small static environments or for troubleshooting purposes. Enter the required settings. For information, see Required fields for Manual mode, page 134. - IKE with Preshared Key: Choose this option to use the Internet Key Exchange protocol to set up a Security Association (SA) for your tunnel. IKE uses a preshared key to authenticate the remote IKE peer. This setting is recommended and is selected by default. Enter the required settings. For more information, see Required fields for IKE with Cisco Small Business RV0xx Series Routers Administration Guide 133

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199

VPN
Setting Up a Gateway to Gateway (Site to Site) VPN
Cisco Small Business RV0xx Series Routers Administration Guide
133
9
-
Dynamic IP +
E-mail Addr.(USER FQDN) Authentication:
Choose this
option if this router has a dynamic IP address and does not have a
Dynamic DNS hostname. Enter any
Email Address
to use for
authentication.
If both routers have dynamic IP addresses (as with PPPoE connections),
do not choose Dynamic IP + Email Addr. for both gateways. For the
remote gateway, choose
IP Address
and
IP Address by DNS Resolved
.
Local/Remote Security Group Type:
Specify the LAN resources that can
use this tunnel. The Local Security Group is for this router’s LAN resources;
the Remote Security Group is for the other router’s LAN resources.
-
IP Address:
Choose this option to specify one device that can use this
tunnel. Then enter the IP address of the device.
-
Subnet:
Choose this option (the default option) to allow all devices on a
subnet to use the VPN tunnel. Then enter the subnetwork IP address and
mask.
-
IP Range:
Choose this option to specify a range of devices that can use
the VPN tunnel. Then identify the range of IP addresses by entering the
first address in the
Begin IP
field and the final address in the
End IP
field.
IPSec Setup
Enter the Internet Protocol Security settings for this tunnel.
IMPORTANT:
In order for any encryption to occur, the two ends of a VPN tunnel
must agree on the methods of encryption, decryption, and authentication. Enter
exactly the same settings on both routers.
Keying Mode:
Choose one of the following key management methods:
-
Manual:
Choose this option if you want to generate the key yourself and
you do not want to enable key negotiation. Manual key management is
used in small static environments or for troubleshooting purposes. Enter
the required settings. For information, see
Required fields for Manual
mode, page 134
.
-
IKE with Preshared Key:
Choose this option to use the Internet Key
Exchange protocol to set up a Security Association (SA) for your tunnel.
IKE uses a preshared key to authenticate the remote IKE peer. This
setting is recommended and is selected by default. Enter the required
settings. For more information, see
Required fields for IKE with