Lantronix X300 Series X300 Series User Guide Rev B - Page 76

: VPN, IPsec (Internet Protocol Security), VPN

Page 76 highlights

9: VPN A Virtual Private Network (VPN) tunnel carries traffic of a private network from one endpoint system to another over a public network such as the Internet. The traffic of a private network so carried over a public network does not know about the existence of the intermediate hops between the two endpoints. Similarly, the intermediate hops are also not aware that they are carrying the network packets that are traversing the tunnel. The tunnel may optionally compress and/or encrypt the data, providing enhanced performance and some measure of security. Note: The X300 series gateways support additional tunneling protocols. For L2TP, PPtP, or GRE protocol configuration, see Interface Protocols. IPsec (Internet Protocol Security) VPN > IPsec The IP Security (IPsec) suite of protocols are designed for cryptographically secure communication at the IP layer. The gateway uses standard IPsec protocol to protect traffic. The identity of communicating users is checked with the user authentication based on pre-shared keys (PSK) or X.509 certificates. The IPsec VPN instance can be started or stopped from the Web UI or by sending an SMS AT+VPN command. See Table 10-16 SMS AT Command Syntax. You can configure a router-to-router VPN connection. To configure an IPsec instance: 1. Go to VPN > IPsec, and click Add. 2. Under Gateway to Gateway, click Add. 3. Enter the VPN configuration details on the General Settings (Table 9-1) and Advanced Settings (Table 9-2) tabs. Parameters Profile Name ProtoType Enable Remote IPsec router Remote Address Remote ID Table 9-1 IPsec General Settings Description Enter the Profile Name to identify the router-to-router IPsec VPN connection. Gateway to Gateway is selected. Check to enable the connection. Enter the remote WAN IP Address or domain name of the remote IPsec router server. Enter the remote LAN IP Address and subnet of the remote IPSEC router server for use on the VPN connection. Enter the ID of the remote network as configured on the remote IPsec router server. X300 Series IoT Cellular Gateway User Guide 76

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216

X300 Series IoT Cellular Gateway User Guide
76
9:
VPN
A Virtual Private Network (VPN) tunnel carries traffic of a private network from one endpoint
system to another over a public network such as the Internet. The traffic of a private network so
carried over a public network does not know about the existence of the intermediate hops between
the two endpoints. Similarly, the intermediate hops are also not aware that they are carrying the
network packets that are traversing the tunnel. The tunnel may optionally compress and/or encrypt
the data, providing enhanced performance and some measure of security.
Note:
The X300 series gateways support additional tunneling protocols. For L2TP,
PPtP, or GRE protocol configuration, see
Interface Protocols
.
IPsec (Internet Protocol Security)
VPN > IPsec
The IP Security (IPsec) suite of protocols are designed for cryptographically secure
communication at the IP layer. The gateway uses standard IPsec protocol to protect traffic. The
identity of communicating users is checked with the user authentication based on pre-shared keys
(PSK) or X.509 certificates.
The IPsec VPN instance can be started or stopped from the Web UI or by sending an SMS
AT+VPN command. See
Table 10-16 SMS AT Command Syntax
.
You can configure a router-to-router VPN connection.
To configure an IPsec instance:
1.
Go to VPN > IPsec, and click
Add
.
2.
Under Gateway to Gateway, click
Add
.
3.
Enter the VPN configuration details on the General Settings (
Table 9-1
) and Advanced
Settings (
Table 9-2
) tabs.
Table 9-1
IPsec General Settings
Parameters
Description
Profile Name
Enter the Profile Name to identify the router–to-router IPsec VPN
connection.
ProtoType
Gateway to Gateway is selected.
Enable
Check to enable the connection.
Remote IPsec router
Enter the remote WAN IP Address or domain name of the remote IPsec
router server.
Remote Address
Enter the remote LAN IP Address and subnet of the remote IPSEC
router server for use on the VPN connection.
Remote ID
Enter the ID of the remote network as configured on the remote IPsec
router server.