Lantronix G520 G520 User Guide - Page 83

Table 9-2, IPsec Advanced Settings, CA Cert., Delete, Single hop IP for watchdog, Monitor interface

Page 83 highlights

9: VPN Parameters CA Cert. Single hop IP for watchdog Monitor interface ping failure Description This field is available if X.509 Certificate is selected in the Key Mode field. The CA certificate file must be uploaded to the /etc/ipsec.d/cacerts directory. Click Select file... to browse the local drive and select the file. Click Upload file... to upload the file. After the file is uploaded, the CA Cert. field displays the file name and time stamp of the upload. To delete a file, click Delete. Enter the IP address to be used for monitoring purposes. The application will ping the IP defined here. If the ping fails, it will restart the device. This could be the LAN IP address of the IPsec router server. Select Yes to ping the IP address defined in Single hop IP for watchdog. Select No if you don't want the monitor interface to ping the single hop IP address. The default is No. Parameters IKE Mode Key Exchange IKE Encryption Table 9-2 IPsec Advanced Settings Description Select the mode that Internet Key Exchange (IKE) protocol uses to authenticate and/or encrypt the peers.  Main  Aggressive Select the mode of encryption key exchange between two communicating peers:  IKEV1  IKEV2  The default mode is IKEV1. Select the cipher type to use for the Internet Key Exchange (IKE):  Any  AES  AES-128  AES-192  AES-256  3DES  DES The default cipher type is "Any". G520 Series IoT Cellular Gateway User Guide 83

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225

9: VPN
G520 Series IoT Cellular Gateway User Guide
83
Table 9-2
IPsec Advanced Settings
CA Cert.
This field is available if X.509 Certificate is selected in the Key Mode
field.
The CA certificate file must be uploaded to the /etc/ipsec.d/cacerts
directory.
Click
Select file...
to browse the local drive and select the file.
Click
Upload file...
to upload the file.
After the file is uploaded, the CA Cert. field displays the file name and
time stamp of the upload.
To delete a file, click
Delete
.
Single hop IP for watchdog
Enter the IP address to be used for monitoring purposes. The
application will ping the IP defined here. If the ping fails, it will restart
the device. This could be the LAN IP address of the IPsec router
server.
Monitor interface ping failure
Select Yes to ping the IP address defined in Single hop IP for
watchdog.
Select No if you don't want the monitor interface to ping the single hop
IP address.
The default is No.
Parameters
Description
IKE Mode
Select the mode that Internet Key Exchange (IKE) protocol uses to
authenticate and/or encrypt the peers.
Main
Aggressive
Key Exchange
Select the mode of encryption key exchange between two
communicating peers:
IKEV1
IKEV2
The default mode is IKEV1.
IKE Encryption
Select the cipher type to use for the Internet Key Exchange (IKE):
Any
AES
AES-128
AES-192
AES-256
3DES
DES
The default cipher type is “Any”.
Parameters
Description