Virtual Private Networks (VPN) IPsec
Digi TransPort WR Routers User Guide
195
n Remote IPNetwork: Enter the IPaddress of the network used for the IPsec tunnel on
the remote side of the tunnel.
n Remote IPNetwork Mask: Enter the IP network mask of the network used for the
IPsec tunnel on the remote side of the tunnel.
n Remote Identifier: Enter the remote identifier for the IPsectunnel. The value for the
Remote Identifier must match the value for the Local Identifier on the remote device at
the other end of the tunnel.
6. Enter the Authentication settings:
a. Authentication Mode: Either Preshared key authentication, or XAuth and
Preshared key authorization.
See IPsec tunnel with XAuth authentication configuration for more information on
using XAuth with IPsec tunnels.
b. IPSecPre-Shared Key: Enter the shared key the device and the remote device use
to authenticate each other.
c. If XAuth and Preshared key authorization is selected for the authentication
mode, the XAuth Identity, Password, and Role options appear. See IPsec tunnel
with XAuth authentication configuration for more information on using XAuth with
IPsec tunnels.
7. Review the Encryption settings and modify as needed. These settings configure the encryption
protocols to use for the IPsec tunnel negotiation.
8. Review the Negotiation settings and modify as needed. These settings configure detailed
negotiation protocols and other options to use for the IPsec tunnel negotiation.
9. Review the Lifetime settings and modify as needed. These settings configure the duration of
the IPsec tunnel before it is renegotiated, and the lifetime of the Internet Key Exchange (IKE)
before the keys are renegotiated.
10. Click Apply.
Modify an existing IPsec tunnel
1. On the menu, click Network > Networks > IPsec > Tunnels.
The IPsec Tunnels page appears.
2. Select an IPsec tunnel and click Edit.
3. Modify the Network, Encryption, Negotiation, and Lifetime settings as needed.
4. Click Apply.
Command line
1. Enable the IPsec tunnel.
digi.router> ipsec 1 state on
2. Enter the IP address or name of the remote device.
digi.router> ipsec 1 peer 47.23.78.32