Skip to main content

IPSec

To access the settings:

  • Follow the menus for VPN
  • IPSec

In the IPSec section, Enable must be selected to activate it.

IPSecConfig-430

ParameterDescriptionDefault Value
Interfacewan_wired, sta, cellular or autoauto
Peer AddressVPN Client/Server, remote endpoint IP address or domain name192.168.0.2
Negotiation ModeMain or AggressiveMain
Tunnel typeSite to site, site to host, host to host, host to siteSite to site
Local subnetIPSec local subnet and mask192.168.1.0/24
Peer subnetIPSec remote subnet and mask192.168.55.0/24
IKE Versionikev1, ikev2ikev2
IKE Encryption AlgorithmPhase 1 IKE encryption algorithm settings. 3DES, AES-128, AES-192, AES-2563DES
IKE Integrity AlgorithmAuthentication settings. SHA-1, SHA2-256, SHA2-512, MD5MD5
Diffie-Hellman GroupDH group settings. Group1(768bits), Group2(1024bits), Group5(1536bits), Group14(2048bits)MD5
IKE LifetimeSetting the lifetime in the IKE phase (seconds)28800
Authentication MethodPre-shared keyPre-shared Key
Pre-shared KeyPre-shared key123456abc
Local IdentifierIP address or FQDN, with the @ prefix, e.g., @domain@client
Peer IdentifierIP address or FQDN, with the @ prefix, e.g., @domain@server
ESP Encryption3DES/AES-128/AES-192/AES-256AES-128
ESP AuthenticationSHA-1/SHA-256/MD5SHA-1
Perfect forward encryption(PFS)None/DH1/DH2/DH5DH2
ESP LifetimeESP lifetime (400 -86400 seconds)3600
DPD TimeoutDPD packet timeout settings60
DPD Detection PeriodWhile DPD detection is ongoing, the time for IPSec protected packet exchange is set60
DPD ActionActions defined for connection detection: 1. None: None 2. Clear: Clear 3. Hold: Wait 4. Restart: RestartRestart

After entering the settings, you must click the Save and Apply buttons to save the settings.