Skip to main content

IPSec

To access the settings:

  • Follow the menus for VPN
  • IPSec

In the IPSec section, Enable must be selected to activate it.

IPSecConfig-430

ParameterDescriptionDefault Value
Interfacewan_4G, wan_wired or autoauto
Remote VPN EndpointVPN Client/Server, remote endpoint IP address or domain name192.168.0.2
Modemain or aggressivemain
Tunnel typeSite to site, site to host, host to host, host to siteSite to site
Local subnetIPSec local subnet and mask192.168.1.0/24
Remote subnetIPSec remote subnet and mask192.168.55.0/24
Local IdentifierIP address or FQDN, with @ prefix, e.g.: @domain@client
Peer IdentifierIP address or FQDN, with @ prefix, e.g.: @domain@server
IKE EncryptionPhase 1 IKE encryption algorithm, authentication and DH group settings3DES/MD5/Group2
IKE LifetimeSetting the lifetime in the IKE phase (seconds)28800
Authentication MethodPre-shared keyPSK
ESP Encryption3DES/AES-128/AES-192/AES-256AES-128
ESP AuthenticationSHA-1/SHA-256/MD5SHA-1
ESP LifetimeESP lifetime (seconds)3600
PFS GroupNone/DH1/DH2/DH5DH2
DPD IntervalWhile DPD detection is ongoing, the time for IPSec protected packet exchange is set60
DPD TimeoutSettings for the timeout of DPD packets60
DPD ActionActions defined for connection detection: 1. None: None 2. Clear: Clear 3. Hold: Wait 4. Restart: RestartRestart

After entering the settings, you must click the Save & Apply button to save the settings.