174 | Aprisa LTE User Manual
Remote Gateway
The public IP address or FQDN of the gateway to establish a connection with. Use 0.0.0.0 if the remote end
will initiate the connection, and any remote address may connect.
IKE Version
The protocol version to allow. IKEv1, IKEv2 or mixed, where IKEv2 is initiated, but can respond on either.
Default value is mixed.
DPD Enabled
When enabled, messages are periodically sent to check that the remote gateway is still active. Default value
is true.
Local/Remote Identity
How this IPsec gateway should be identified for authentication.
• If left blank it defaults to local/remote IP address used for IKE negotiation.
• If ‘IKE Authentication Method’ is configured as ‘Pre Shared Key’, the identity can be specified in
format such as IP address (1.2.3.4), user FQDN (user@domain.com) or FQDN (domain.com) or any
text value.
• If ‘IKE Authentication Method’ is configured as ‘Certificate’, the identity has to be confirmed by the
certificate, such that it has to match the full subject DN or one of the subjectAltName extensions
contained in the certificate.
Make sure the ‘Local Identity’ specified on this IPsec gateway is configured as ‘Remote Identify’ on remote
IPsec gateway.
IKE Authentication Method
How the two gateways should authenticate each other. Either Pre-Shared Key (PSK) or Certificate. If
certificate is chosen, ensure that a ROOT_CA certificate is uploaded that will verify the remote gateway. If
more than one ROOT_CA certificate is uploaded, then only one of them need match to allow remote
authentication.
IKE Authentication Pre-Shared Key
Shared secret if authentication method is “pre-shared-key”. The shared secret should be same on both the
IPsec gateways.
IKE Authentication Certificate
If authentication method is ‘Certificate’, select a Device Certificate previously uploaded on the Certificate
page. This is used to identify this gateway to remote device.
IKE Authentication Private Key
The private key file that matches the certificate specified in ‘IKE Authentication Certificate’.
IKE Authentication Private Key Passphrase
The passphrase to decrypt the private key file (if required).
IKE Proposal Authentication Algorithm
Authentication algorithm to be used during negotiation.