TP-Link TL-ER6020 TL-ER6020 v1 User Guide - Page 94

Local Subnet, Remote Subnet, Remote Gateway, Policy Mode, IKE Policy, IPsec Proposal

Page 94 highlights

Mode: Local Subnet: Remote Subnet: WAN: Remote Gateway: Policy Mode:  IKE Mode IKE Policy: IPsec Proposal: PFS: Select the network mode for IPsec policy. Options include:  LAN-to-LAN: Select this option when the client is a network.  Client-to-LAN: Select this option when the client is a host. Specify IP address range on your local LAN to identify which PCs on your LAN are covered by this policy. It's formed by IP address and subnet mask. Specify IP address range on your remote network to identify which PCs on the remote network are covered by this policy. It's formed by IP address and subnet mask. Specify the local WAN port for this Policy. The "Remote Gateway" of the remote peer should be set to the IP address of this WAN port. Enter the Remote Gateway. It can be IP address or Domain name. Select the negotiation mode for the policy.  IKE: The parameters for the VPN tunnel are generated automatically via IKE negotiations.  Manual: All settings (including the keys) for the VPN tunnel are manually inputted and no key negotiation is needed. It is available when IKE is selected as the negotiation mode. Specify the IKE policy. If there is no policy selection, add new policy on VPN→IKE→IKE Policy page. Select IPsec Proposal on IKE mode. Up to four IPsec Proposals can be selected on IKE mode. Select the PFS (Perfect Forward Security) for IKE mode to enhance security. This setting should match the remote peer. With PFS feature, IKE negotiates to create a new key in -89-

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168

-89-
Mode:
Select the network mode for IPsec policy. Options include:
LAN-to-LAN: Select this option when the client is a
network.
Client-to-LAN: Select this option when the client is a host.
Local Subnet:
Specify IP address range on your local LAN to identify which
PCs on your LAN are covered by this policy. It's formed by IP
address and subnet mask.
Remote Subnet:
Specify IP address range on your remote network to identify
which PCs on the remote network are covered by this policy. It's
formed by IP address and subnet mask.
WAN:
Specify the local WAN port for this Policy. The "Remote
Gateway" of the remote peer should be set to the IP address of
this WAN port.
Remote Gateway:
Enter the Remote Gateway. It can be IP address or Domain
name.
Policy Mode:
Select the negotiation mode for the policy.
IKE: The parameters for the VPN tunnel are generated
automatically via IKE negotiations.
Manual: All settings (including the keys) for the VPN tunnel
are manually inputted and no key negotiation is needed.
IKE Mode
IKE Policy:
It is available when IKE is selected as the negotiation mode.
Specify the IKE policy. If there is no policy selection, add new
policy on
VPN
IKE
IKE Policy
page.
IPsec Proposal:
Select IPsec Proposal on IKE mode. Up to four IPsec Proposals
can be selected on IKE mode.
PFS:
Select the PFS (Perfect Forward Security) for IKE mode to
enhance security. This setting should match the remote peer.
With PFS feature, IKE negotiates to create a new key in