D-Link DWC-1000 DWC-1000 User's Guide - Page 98

Enter the last IP address in the range. If Local / Remote IP = Single, leave the End IP Address

Page 98 highlights

VPN Settings Field Description Local / Remote IP Local / Remote Start IP Address Select the type of identifier that you want to provide for the endpoint. Choices are: • Any = policy is for traffic from the given end point (local or remote). Note that selecting Any for both local and remote end points is not valid. • Single = limits the policy to one host. Enter the IP address of the host that will be part of the VPN in the Start IP Address field. • Range = allows computers within an IP address range to connect to the VPN. Enter the Start IP Address and End IP Address in the provided fields. • Subnet = allows an entire subnet to connect to the VPN. Enter the network address in the Start IP Address field and enter the Subnet Mask in the Subnet Mask field. Enter the first IP address in the range. Local / Remote End IP Address Enter the last IP address in the range. If Local / Remote IP = Single, leave the End IP Address field blank. Local / Remote Subnet Mask Local / Remote Prefix Length If Local / Remote IP = Subnet, enter the Subnet Mask of the network. Do not use overlapping subnets for remote or local traffic selectors. Otherwise, you must add static routes on the wireless controller and the hosts to be used. Example of a combination to avoid is: • Local Traffic Selector = 192.168.75.0/24 • Remote Traffic Selector = 192.168.0.0./16. If Local / Remote IP = Subnet and Protocol = IPv6, enter the prefix length of the network. Enable Keepalive Source IP Address Determined whether the wireless controller sends ping packets periodically to the host on the peer side of the network to keep the tunnel alive. Choices are: • Checked = enables Keepalive. • Unchecked = disables Keepalive. If Enable Keepalive is checked, enter the IP address from which ping packet must be sent. Destination IP Address If Enable Keepalive is checked, enter the IP Address to which ping packet needs to be sent. Detection Protocol If Enable Keepalive is checked, specify how often the wireless controller sends ping packets. Reconnect After Failure Count If Enable Keepalive is checked, fresh negotiation starts when no acknowledgement is received for the number of consecutive packets specified here. Phase (IKE SA Parameters) These settings are applicable for Auto IPsec policies that use IKE to perform negotiations between the two VPN endpoints. Exchange Mode Direction / Type NAT Traversal IKE phase can occur in one of two exchange modes. Select an exchange mode. Choices are: • Main = negotiates the tunnel with higher security, but is slower than aggressive mode. • Aggressive = fewer exchanges are made and with fewer packets than main mode, allowing this mode to establish a faster connection than main mode, but with lower security. Select a connection method. Choices are: • Initiator = wireless controller initiates the connection to the remote end. • Responder = wireless controller waits passively and responds to remote IKE requests. • Both = wireless controller work in either Initiator or Responder mode. Enables or disables Network Address Translation (NAT) traversal. Choices are: • On = select this setting if you expect any NAT to occur during IPsec communication. • Off = select this setting if you do not expect NAT to occur during IPsec communication. 98 DWC-1000 Wireless Controller User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242

VPN Settings
98
DWC-1000 Wireless Controller User’s Guide
Field
Description
Local / Remote IP
Select the type of identifier that you want to provide for the endpoint. Choices are:
Any = policy is for traffic from the given end point (local or remote). Note that selecting Any for
both local and remote end points is not valid.
Single = limits the policy to one host. Enter the IP address of the host that will be part of the
VPN in the Start IP Address field.
Range = allows computers within an IP address range to connect to the VPN. Enter the Start
IP Address and End IP Address in the provided fields.
Subnet = allows an entire subnet to connect to the VPN. Enter the network address in the
Start IP Address field and enter the Subnet Mask in the Subnet Mask field.
Local / Remote Start IP Address
Enter the first IP address in the range.
Local / Remote End IP Address
Enter the last IP address in the range. If Local / Remote IP = Single, leave the End IP Address
field blank.
Local / Remote Subnet Mask
If Local / Remote IP = Subnet, enter the Subnet Mask of the network. Do not use overlapping
subnets for remote or local traffic selectors. Otherwise, you must add static routes on the
wireless controller and the hosts to be used. Example of a combination to avoid is:
Local Traffic Selector = 192.168.75.0/24
Remote Traffic Selector = 192.168.0.0./16.
Local / Remote Prefix Length
If Local / Remote IP = Subnet and Protocol = IPv6, enter the prefix length of the network.
Enable Keepalive
Determined whether the wireless controller sends ping packets periodically to the host on the
peer side of the network to keep the tunnel alive. Choices are:
Checked = enables Keepalive.
Unchecked = disables Keepalive.
Source IP Address
If Enable Keepalive is checked, enter the IP address from which ping packet must be sent.
Destination IP Address
If Enable Keepalive is checked, enter the IP Address to which ping packet needs to be sent.
Detection Protocol
If Enable Keepalive is checked, specify how often the wireless controller sends ping packets.
Reconnect After Failure Count
If Enable Keepalive is checked, fresh negotiation starts when no acknowledgement is received
for the number of consecutive packets specified here.
Phase (IKE SA Parameters)
These settings are applicable for Auto IPsec policies that use IKE to perform negotiations between the two VPN endpoints.
Exchange Mode
IKE phase can occur in one of two exchange modes. Select an exchange mode. Choices are:
Main = negotiates the tunnel with higher security, but is slower than aggressive mode.
Aggressive = fewer exchanges are made and with fewer packets than main mode, allowing
this mode to establish a faster connection than main mode, but with lower security.
Direction / Type
Select a connection method. Choices are:
Initiator = wireless controller initiates the connection to the remote end.
Responder = wireless controller waits passively and responds to remote IKE requests.
Both = wireless controller work in either Initiator or Responder mode.
NAT Traversal
Enables or disables Network Address Translation (NAT) traversal. Choices are:
On = select this setting if you expect any NAT to occur during IPsec communication.
Off = select this setting if you do not expect NAT to occur during IPsec communication.