WRVS4400N User Guide                        71
VPN Tab
Setting Up and Configuring the Router
Local Security Group Type—Select the local LAN user(s) behind the router that can use this 
VPN tunnel. This may be a single IP address or Sub-network. Notice that the Local Secure Group 
must match the other router's Remote Secure Group. 
IP Address—Enter the IP address on the local network. 
Subnet Mask—If the "Subnet" option is selected, enter the mask to determine the IP addresses 
on the local network. 
Remote Group Setup
Remote Security Gateway Type—There are two types. They are IP Only, IP + Domain Name 
(FQDN) Authentication. The type of Remote Security Gateway should match with the Local 
Security Gateway Type of VPN devices in the other end of tunnel. 
• IP Only—If you select IP Only, only the specific IP Address that you enter will be able to 
access the tunnel. It's the IP Address of the remote VPN Router or device which you wish 
to communicate. The remote VPN device can be another VPN Router or a VPN Server. If 
you know the static IP address of remote VPN device, select IP address from drop-down 
menu. If you don't know the static IP address of remote VPN device, but the domain 
name of remote VPN device is known, you can select IP by DNS Resolved, and enter the 
real domain name on the Internet. WRVS4400N will get the IP address of remote VPN 
device by DNS Resolved, and IP address of remote VPN device will be displayed on VPN 
Status of Summary page
• IP + Domain Name (FQDN) Authentication—If you select this type, enter the FQDN 
(Fully Qualified Domain Name) and IP address of the VPN device at the other end of the 
tunnel. If you know the static IP address of remote VPN device, select IP address from 
drop-down menu. If you don't know the static IP address of remote VPN device, but the 
domain name of remote VPN device is known, you can select IP by DNS Resolved, and 
enter the real domain name on the Internet. WRVS4400N will get the IP address of 
remote VPN device by DNS Resolved, and IP address of remote VPN device will be 
displayed on VPN Status of Summary page. Then, enter the Domain Name as an ID, it 
can be not a real domain name on Internet. The IP and Domain Name ID must be same 
with the Local Gateway of the remote VPN device, and the same IP and Domain Name ID 
can be only for one tunnel connection.
Remote Security Group—Select the remote LAN user(s) behind the remote gateway who can 
use this VPN tunnel. This may be a single IP address, a Sub-network, or any addresses. If "Any" is 
set, the router acts as responder and accepts request from any remote user. Notice that the 
Remote Secure Group must match the other router's Local Secure Group. 
IP Address—Enter the IP address on the local network. 
Subnet Mask—If the "Subnet" option is selected, enter the mask to determine the IP addresses 
on the local network.
Remote Security Gateway—Select the desired option - IP address. 
IP—The IP address in this field must match the public IP address (i.e. WAN IP Address) of the 
remote gateway at the other end of this tunnel.