Lantronix EMG 8500 EMG User Guide - Page 121

Remote Peer, Remote Id, Remote Subnets, Remote Source IP, config, CIDR Notation, P Address Range

Page 121 highlights

Remote Peer Remote Id Remote Subnet(s) Remote Source IP Local IP Address Local Id 7: Networking The IP address or FQDN of the remote host's public network interface. The special value of any can be entered to signify an address to be filled in by automatic keying during negotiation. The console manager will act as a responder/server. How the remote host should be identified for authentication. The Id is used to select the proper credentials for communicating with the remote host. One or more allowed subnets behind the remote host, expressed in CIDR notation (IP address/mask bits). If multiple subnets are specified, the subnets should be separated by a comma. Up to 10 local subnets supported. Configured subnets of the peers may differ, the protocol narrows it to the greatest common subnet. In IKEv1, this may lead to problems with other implementations. Make sure to configure identical subnets in such configurations. If the remote subnet is not defined, it will be assumed that the remote end of the connection goes to the remote peer only. The internal source IP to use in a tunnel(Virtual IP). Currently the accepted values are config, CIDR Notation, IP Address Range or poolname. If the value is config on the responder side, the initiator must propose an address which is then echoed back. The supported address pools are expressed as CIDR notation and IP Address range as - or the use of an external IP address pool using poolname is the name of the IP address pool used for the lookup. In the IP address of the EMG (local) side of the tunnel, specifically the public-network interface. If the IP address is not given, the value %any will be used in the ipsec.conf file (this is the default). It signifies that the IP address will be filled (by automatic keying) during negotiation. If EMG initiates the connection setup the routing table will be queried to determine the correct local IP address. In case the EMG is responding to a connection setup then any IP address that is assigned to a local interface will be accepted. For EMG with a cellular modem, if Local IP Address is configured to be the same as the IP address of the cellular modem acquired via DHCP; whenever the IP address of the cellular modem changes, the Local IP Address of the VPN tunnel will be automatically updated to be the same as the new cellular modem IP address. Note:  This features is only available when the Tunnel Restart option is selected.  If Local IP Address is set to the IP address of a network interface that acquires its IP address from DHCP, we recommend you to configure DHCP to always assign the same IP address to the interface. Otherwise, if the interface is assigned with a new IP address, the VPN tunnel will stop working. To fix this issue, you will have to update the Local IP Address and restart the tunnel. How the EMG should be identified for authentication. The Id is used by the remote host to select the proper credentials for communicating with the EMG. EMG™ Edge Management Gateway User Guide 121

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495

7: Networking
EMG™ Edge Management Gateway User Guide
121
Remote Peer
The IP address or FQDN of the remote host's public network interface. The
special value of
any
can be entered to signify an address to be filled in by
automatic keying during negotiation. The console manager will act as a
responder/server.
Remote Id
How the remote host should be identified for authentication. The Id is used
to select the proper credentials for communicating with the remote host.
Remote Subnet(s)
One or more allowed subnets behind the remote host, expressed in CIDR
notation (IP address/mask bits). If multiple subnets are specified, the
subnets should be separated by a comma. Up to 10 local subnets
supported.
Configured subnets of the peers may differ, the protocol narrows it to the
greatest common subnet. In IKEv1, this may lead to problems with other
implementations. Make sure to configure identical subnets in such
configurations.
If the remote subnet is not defined, it will be assumed that the remote end of
the connection goes to the remote peer only.
Remote Source IP
The internal source IP to use in a tunnel(Virtual IP). Currently the accepted
values are
config
,
CIDR Notation
, I
P Address Range
or
poolname
. If the
value is config on the responder side, the initiator must propose an address
which is then echoed back. The supported address pools are expressed as
CIDR notation and IP Address range as - or the use of an external IP
address pool using poolname is the name of the IP address pool used for
the lookup.
Local IP Address
In the IP address of the EMG (local) side of the tunnel, specifically the
public-network interface. If the IP address is not given, the value
%any
will
be used in the
ipsec.conf
file (this is the default). It signifies that the IP
address will be filled (by automatic keying) during negotiation. If EMG
initiates the connection setup the routing table will be queried to determine
the correct local IP address. In case the EMG is responding to a connection
setup then any IP address that is assigned to a local interface will be
accepted.
For EMG with a cellular modem, if
Local IP Address
is configured to be the
same as the IP address of the cellular modem acquired via DHCP;
whenever the IP address of the cellular modem changes, the
Local IP
Address
of the VPN tunnel will be automatically updated to be the same as
the new cellular modem IP address.
Note:
This features is only available when the
Tunnel Restart
option is
selected.
If
Local IP Address
is set to the IP address of a network interface that
acquires its IP address from DHCP, we recommend you to configure
DHCP to always assign the same IP address to the interface.
Otherwise, if the interface is assigned with a new IP address, the VPN
tunnel will stop working. To fix this issue, you will have to update the
Local IP Address and restart the tunnel.
Local Id
How the EMG should be identified for authentication. The Id is used by the
remote host to select the proper credentials for communicating with the
EMG.