Industrial Cellular VPN Router NR500 Series User Manual
Page 63 / 78
• Enable
Select Enable will launch the IPSec process.
• Description
Enter a description for this IPSec VPN tunnel.
• Remote Gateway
Enter the IP address of the remote endpoint of the tunnel.
• IKE Version
Internet Key Exchange, select from “IKEv1” or “IKEv2”.
• Connection Type
Select from “Tunnel” or “Transport”.
Tunnel: In tunnel mode, the entire IP packet is encrypted and authenticated. It is then encapsulated
into a new IP packet with a new IP header. Tunnel mode is used to create virtual private networks for
network-to-network communications.
Transport: In transport mode, only the payload of the IP packet is usually encrypted or authenticated.
The routing is intact, since the IP header is neither modified nor encrypted.
• Negotiation Mode
Select from “Main” or “Aggressive”.
• Authentication Method
Select from “Pre-shared Key” or “Pre-shared Key and Xauth”.
• Local Subnet
Ener the IP address with mask if a network beyond the local LAN will be sending packets through the
tunnel.
NOTE: The Remote subnet and Local subnet addresses must not overlap!
• Local Pre-shared Key
Enter the pre-shared key which match the remote endpoint.
• Local ID Type
The local endpoint's identification. The identifier can be a host name or an IP address.
• Xauth Identity
Enter Xauth identity after “Pre-shared Key and Xauth” on authentication Method is enabled.
• Xauth Password
Enter Xauth password “Pre-shared Key and Xauth” on authentication Method is enabled.
• Remote Subnet
Enter an IP address with mask if encrypted packets are also destined for the specified network that is
beyond the Remote IP Address.
NOTE: The Remote subnet and Local subnet addresses must not overlap!
• Remote ID Type
The authentication address of the remote endpoint.