IPSec
To access the settings:
- Follow the menus for VPN
- IPSec
In the IPSec section, Enable must be selected to activate it.

| Parameter | Description | Default Value |
|---|---|---|
| Interface | wan_wired, sta, cellular or auto | auto |
| Peer Address | VPN Client/Server, remote endpoint IP address or domain name | 192.168.0.2 |
| Negotiation Mode | Main or Aggressive | Main |
| Tunnel type | Site to site, site to host, host to host, host to site | Site to site |
| Local subnet | IPSec local subnet and mask | 192.168.1.0/24 |
| Peer subnet | IPSec remote subnet and mask | 192.168.55.0/24 |
| IKE Version | ikev1, ikev2 | ikev2 |
| IKE Encryption Algorithm | Phase 1 IKE encryption algorithm settings. 3DES, AES-128, AES-192, AES-256 | 3DES |
| IKE Integrity Algorithm | Authentication settings. SHA-1, SHA2-256, SHA2-512, MD5 | MD5 |
| Diffie-Hellman Group | DH group settings. Group1(768bits), Group2(1024bits), Group5(1536bits), Group14(2048bits) | MD5 |
| IKE Lifetime | Setting the lifetime in the IKE phase (seconds) | 28800 |
| Authentication Method | Pre-shared key | Pre-shared Key |
| Pre-shared Key | Pre-shared key | 123456abc |
| Local Identifier | IP address or FQDN, with the @ prefix, e.g., @domain | @client |
| Peer Identifier | IP address or FQDN, with the @ prefix, e.g., @domain | @server |
| ESP Encryption | 3DES/AES-128/AES-192/AES-256 | AES-128 |
| ESP Authentication | SHA-1/SHA-256/MD5 | SHA-1 |
| Perfect forward encryption(PFS) | None/DH1/DH2/DH5 | DH2 |
| ESP Lifetime | ESP lifetime (400 -86400 seconds) | 3600 |
| DPD Timeout | DPD packet timeout settings | 60 |
| DPD Detection Period | While DPD detection is ongoing, the time for IPSec protected packet exchange is set | 60 |
| DPD Action | Actions defined for connection detection: 1. None: None 2. Clear: Clear 3. Hold: Wait 4. Restart: Restart | Restart |
After entering the settings, you must click the Save and Apply buttons to save the settings.