D-Link DWC-1000 DWC-1000 User's Guide - Page 97

VPN Settings, Checked = enable Mode Config. If you enable Mode Config, con the Mode Config

Page 97 highlights

VPN Settings Field Description IKE Version IPsec Mode Select Local Gateway Select the IKE version to be used. Choices are: • IKEv1 • IKEv2 Select the IPsec mode. Choices are: • Tunnel Mode = most commonly used between gateways, or at an end-station to a gateway, the gateway acting as a proxy for the hosts behind it. • Transport Mode = used between end-stations or between an end-station and a gateway, if the gateway is being treated as a host - for example, an encrypted Telnet session from a workstation to a router, in which the wireless controller is the actual destination. If two Option ports are configured to connect to an ISP, select the gateway that will be used as the local endpoint for this IPsec tunnel. Remote Endpoint Enable Mode Config Enable NetBIOS Enable RollOver Protocol Select the type of identifier that you want to provide for the gateway at the remote endpoint. Choices are: • IP Address • FQDN Enables or disables the Mode Config feature. Mode Config is similar to DHCP and is used to assign IP addresses to remote VPN clients, like iPhone VPN Client. Choices are: • Checked = enable Mode Config. If you enable Mode Config, configure the Mode Config settings (see "Mode Config Settings" on page 109). • Unchecked = disable Mode Config. Determined whether NetBIOS broadcasts travel over the VPN tunnel. For client policies, the NetBIOS feature is available by default. Choices are: • Checked = allows NetBIOS broadcasts to travel over the VPN tunnel • Unchecked = disables NetBIOS broadcasts over the VPN tunnel. Determines whether the VPN will roll over when Option Mode is set to Auto Rollover on the Option Mode page. Choices are: • Checked = allows the VPN to roll over when Option Mode is set to Auto Rollover on the Option Mode page. • Unchecked = disables VPN rollover. Enable DHCP Determines whether VPN clients obtain an assigned IP address using DHCP when they connect to the wireless controller over IPsec. Choices are: • Checked = VPN clients get an IP address. • Unchecked = VPN clients do not get an IP address. Tunnel mode IPsec policies require local and remote traffic settings to be defined. For both local and remote endpoints configure the following settings. 97 DWC-1000 Wireless Controller User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242

VPN Settings
97
DWC-1000 Wireless Controller User’s Guide
Field
Description
IKE Version
Select the IKE version to be used. Choices are:
IKEv1
IKEv2
IPsec Mode
Select the IPsec mode. Choices are:
Tunnel Mode = most commonly used between gateways, or at an end-station to a gateway,
the gateway acting as a proxy for the hosts behind it.
Transport Mode = used between end-stations or between an end-station and a gateway, if the
gateway is being treated as a host — for example, an encrypted Telnet session from a
workstation to a router, in which the wireless controller is the actual destination.
Select Local Gateway
If two Option ports are configured to connect to an ISP, select the gateway that will be used as
the local endpoint for this IPsec tunnel.
Remote Endpoint
Select the type of identifier that you want to provide for the gateway at the remote endpoint.
Choices are:
IP Address
FQDN
Enable Mode Config
Enables or disables the Mode Config feature. Mode Config is similar to DHCP and is used to
assign IP addresses to remote VPN clients, like iPhone VPN Client. Choices are:
Checked = enable Mode Config. If you enable Mode Config, configure the Mode Config
settings (see “Mode Config Settings” on page 109).
Unchecked = disable Mode Config.
Enable NetBIOS
Determined whether NetBIOS broadcasts travel over the VPN tunnel. For client policies, the
NetBIOS feature is available by default. Choices are:
Checked = allows NetBIOS broadcasts to travel over the VPN tunnel
Unchecked = disables NetBIOS broadcasts over the VPN tunnel.
Enable RollOver
Determines whether the VPN will roll over when Option Mode is set to Auto Rollover on the
Option Mode page. Choices are:
Checked = allows the VPN to roll over when Option Mode is set to Auto Rollover on the Option
Mode page.
Unchecked = disables VPN rollover.
Protocol
Enable DHCP
Determines whether VPN clients obtain an assigned IP address using DHCP when they connect
to the wireless controller over IPsec. Choices are:
Checked = VPN clients get an IP address.
Unchecked = VPN clients do not get an IP address.
Tunnel mode IPsec policies require local and remote traffic settings to be defined. For both local and remote endpoints configure the
following settings.