D-Link DSR-1000AC User Manual - Page 111

Field, Description

Page 111 highlights

Section 7 - VPN Field Policy Name Policy Type IP Protocol Version IKE Version L2TP Mode IPSec Mode Select Local Gateway Remote Endpoint IP Address/FQDN Enable Mode Config Enable NetBIOS Enable RollOver Protocol Enable DHCP Local IP/Remote IP Description Enter a unique name for the VPN Policy. This name is not an identifier for the remote WAN/client. Select either Manual or Auto. • Manual: All settings (including the keys) for the VPN tunnel are manually input for each end point. No third-party server or organization is involved. • Auto: Some parameters for the VPN tunnel are generated automatically. This requires using the IKE (Internet Key Exchange) protocol to perform negotiations between the two VPN Endpoints. Select either IPv4 or IPv6. Select the version of IKE. Select the L2TP mode. Select either Tunnel or Transport. IPsec tunnel mode is useful for protecting traffic between different networks, when traffic must pass through an intermediate, untrusted network. Tunnel mode is primarily used for interoperability with gateways, or end-systems that do not support L2TP/IPsec or PPTP connections. Transport mode is the default mode for IPsec, and it is used for end-to-end communications (for example, for communications between a client and a server). In the event that two WAN ports are configured to connect to your ISP, select the gateway that will be used as the local endpoint for this IPsec tunnel. Select the type of identifier that you want to provide for the router at the remote endpoint (either IP Address or FQDN [Fully Qualified Domain Name]) Enter the identifier for the router. Toggle to ON to enable. Mode Config is similar to DHCP and is used to assign IP addresses to the remote VPN clients. Toggle to ON to allow NetBIOS broadcasts to travel over the VPN tunnel Toggle to ON to enable VPN rollover. You must have the WAN Mode set to Rollover. Select a protocol from the drop-down menu. Toggle to ON to allow VPN clients that are connected to your router over IPsec to receive an assigned IP using DHCP. Select the type of identifier that you want to provide for the endpoint: • Any: Specifies that the policy is for traffic from the given end point (local or remote). Note that selecting Any for both local and remote end points is not valid. • Single: Limits the policy to one host. Enter the IP address of the host that will be part of the VPN. • Range: Allows computers within an IP address range to connect to the VPN. Enter the Start IP Address and End IP Address in the provided fields. • Subnet: Allows an entire subnet to connect to the VPN. Enter the network address and subnet mask in the provided fields. D-Link DSR-Series User Manual 98

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348

D-Link DSR-Series User Manual
98
Section 7 - VPN
Field
Description
Policy Name
Enter a unique name for the VPN Policy. This name is not an identifier for the remote WAN/client.
Policy Type
Select either
Manual
or
Auto
.
• Manual: All settings (including the keys) for the VPN tunnel are manually input for each end point. No
third-party server or organization is involved.
• Auto: Some parameters for the VPN tunnel are generated automatically. This requires using the IKE
(Internet Key Exchange) protocol to perform negotiations between the two VPN Endpoints.
IP Protocol Version
Select either
IPv4
or
IPv6
.
IKE Version
Select the version of IKE.
L2TP Mode
Select the L2TP mode.
IPSec Mode
Select either
Tunnel
or
Transport
. IPsec tunnel mode is useful for protecting traffic between different
networks, when traffic must pass through an intermediate, untrusted network. Tunnel mode is primarily
used for interoperability with gateways, or end-systems that do not support L2TP/IPsec or PPTP
connections. Transport mode is the default mode for IPsec, and it is used for end-to-end communications
(for example, for communications between a client and a server).
Select Local Gateway
In the event that two WAN ports are configured to connect to your ISP, select the gateway that will be used
as the local endpoint for this IPsec tunnel.
Remote Endpoint
Select the type of identifier that you want to provide for the router at the remote endpoint (either
IP
Address
or
FQDN
[Fully Qualified Domain Name])
IP Address/FQDN
Enter the identifier for the router.
Enable Mode Config
Toggle to
ON
to enable. Mode Config is similar to DHCP and is used to assign IP addresses to the remote
VPN clients.
Enable NetBIOS
Toggle to
ON
to allow NetBIOS broadcasts to travel over the VPN tunnel
Enable RollOver
Toggle to
ON
to enable VPN rollover. You must have the WAN Mode set to Rollover.
Protocol
Select a protocol from the drop-down menu.
Enable DHCP
Toggle to
ON
to allow VPN clients that are connected to your router over IPsec to receive an assigned IP
using DHCP.
Local IP/Remote IP
Select the type of identifier that you want to provide for the endpoint:
Any:
Specifies that the policy is for traffic from the given end point (local or remote). Note that
selecting Any for both local and remote end points is not valid.
Single:
Limits the policy to one host. Enter the IP address of the host that will be part of the VPN.
Range:
Allows computers within an IP address range to connect to the VPN. Enter the Start IP Address
and End IP Address in the provided fields.
Subnet:
Allows an entire subnet to connect to the VPN. Enter the network address and subnet mask
in the provided fields.