Virtual Private Networking
127
 N300 Wireless ADSL2+ Modem Router DGN2200v3
•     Single/Start IP Address. Enter the IP address for a single address, or the starting 
address for an address range. A single address setting is used when you want to make a 
single server on your LAN available to remote users. A range has to be an address range 
used on your LAN. Any. The remote VPN endpoint might be at any IP address.
•     Finish IP Address. For an address range, enter the finish IP address. This needs to be 
an address range used on your LAN. 
VPN Auto Policy Remote LAN Settings
The remote VPN endpoint has to have these IP addresses entered as its local addresses.
•     IP Address. If there is no LAN (only a single PC) at the remote endpoint, select Single 
PC - no Subnet option. If this option is selected, no additional data is required. The 
typical application is a PC running the VPN client at the remote end.
•     Single/Start IP Address. Enter an IP address that is on the remote LAN. You can use 
this setting when you want to access a server on the remote LAN. 
- For a range of addresses, enter the starting IP address. This needs to be an address 
range used on the remote LAN. 
- Any. Any outgoing traffic from the computers in the Local IP fields triggers an 
attempted VPN connection to the remote VPN endpoint. Be sure you want this option 
before selecting it.
•     Finish IP Address. Enter the finish IP address for a range of addresses. This has to be an 
address range used on the remote LAN. 
•     Subnet Mask. Enter the network mask.
VPN Auto Policy IKE Settings
•     Direction. This setting is used when the modem router determines if the IKE policy 
matches the current traffic. Select an option. 
- Responder only. Incoming connections are allowed, but outgoing connections are 
blocked. 
- Initiator and Responder. Both incoming and outgoing connections are allowed. 
•     Exchange Mode. Ensure that the remote VPN endpoint is set to use Main Mode.
•     Diffie-Hellman (DH) Group. The Diffie-Hellman algorithm is used when keys are 
exchanged. The DH Group setting determines the bit size used in the exchange. This 
value needs to match the value used on the remote VPN gateway.
•     Local Identity Type. Select an option to match the Remote Identity Type setting on the 
remote VPN endpoint. 
- WAN IP Address. Your Internet IP address. 
- Fully Qualified Domain Name. Your domain name. 
- Fully Qualified User Name. Your name, email address, or other ID.
- Local Identity Data. Enter the data for the local identity type that you selected. (If 
WAN IP Address is selected, no input is required.)