Configuring Virtual Private Networking (VPN) Configure Internet Protocol security (IPsec)
Digi TransPort® Routers User Guide
475
Use a.b.c.d as a backup unit
The IP address or hostname of a backup peer. If the router cannot open a connection to the
primary peer, it uses this configuration. The backup peer device must have an identical IPsec
tunnel configuration as the primary peer.
Local LAN
Use these settings for the local LAN
The local LAN subnet settings on the IPsec tunnel.
IP Address
Use this IP address for the local LAN subnet. This is usually the IP address of the router’s
Ethernet interface or that of a specific device on the local subnet (such as a PC running a client
or host application).
Mask
Use this IP mask for the local LAN subnet. The mask sets the range of IP addresses that will be
allowed to use the IPsec tunnel.
Use interface x,y
Use the IP address and mask of the specified interface.
Remote LAN
Use these settings for the remote LAN
These define the remote LAN subnet settings on the IPsec tunnel.
IP Address
Use this IP address for the remote LAN subnet. This is usually the IP address of the peer’s
Ethernet interface or that of a specific device on the local subnet (such as a PC running a client
or host application).
Mask
Use this IP mask for the remote LAN subnet. The mask sets the range of IP addresses that will
be allowed to use the IPsec tunnel.
Remote Subnet ID
L2TP/IPsec VPNs normally use this setting. When the router is in server mode and negotiating
IPsec from behind a NAT box, this parameter should be configured to the ID sent by the remote
Windows client (this is usually the computer name).
Use the following security on this tunnel
The security identities on the IPsec tunnel.