Digi ConnectPort X4 Guía de usuario Pagina 81

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 271
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 80
Configuration through the web interface
81
VPN tunnel configuration settings
Description: Enter a short, one-line description of the VPN tunnel.
VPN Tunnel: Displays settings for encryption and authentication keys. Selecting
ISAKMP is recommended; it is the standard protocol used by almost all VPN devices.
ISAKMP is more secure than manually setting the keys The only time to set the keys
manually is when connecting with an old VPN device that does not support ISAKMP, in
which case you should replace the obsolete box with one that does.
Local Endpoint Type:
Select Local endpoint is a subnet to allow devices on the remote network to see
devices on the local network. This is the standard way IPsec works and the correct
choice in most cases.
Select Local endpoint is an internal interface to not allow devices on the remote
network to see devices on the local network. This causes the Digi device to create a
virtual endpoint and assign it the IP address specified later in the settings on this page.
Devices on the remote network will only see the IP address of this endpoint, and cannot
see the IP addresses of any devices on the local private network. This feature must be
used in combination with NAT. If you select it, then you must update the NAT settings
on the Network >IP Forwarding page. You must enable NAT translation for the VPN
interface that corresponds to the tunnel. Tunnel 1 uses interface vpn0, tunnel 2 uses
vpn1, etc.
VPN Mode:
If a single remote VPN device will be used for this VPN tunnel, select
Initiate client connections to and accept connections from the remote VPN device
at and enter the remote device’s IP address or DNS name in the field below. If the Digi
device should accept connections from any remote VPN device for this tunnel, select the
Accept connections from any VPN device option.
Identity settings
Network Interface: mobile|0eth0: Select the network interface used to communicate
with the remote VPN device. The mobile0 device is the one with the cellular modem. In
most cases, this is the correct device to use to communicate with a remote VPN device
on the Internet.
Negotiate tunnel as soon as interface comes up: Check if the Digi device should
establish the VPN tunnel as soon as the selected network interface is ready to use. Leave
this box unchecked if the Digi device should wait until a device on the local private
network attempts to communicate with a device on the remote network before
establishing the VPN tunnel.
Use the following as the identity: Use this option to control how the Digi device
identifies itself to the remote VPN device. The Digi device must identify itself to the
remote VPN device when it negotiates the tunnel. You must make sure both devices
agree on what the identification is. Select the “Use the following as the identity” option
to enter a string such as a DNS name or an FQDN. Select the “Use the interface IP
address” if the Digi device should send the IP address of the interface you selected
above as its identity. Select Use the identify certificate X.509… to use a PKI
certificate. If using a PKI certificate, remember to load it in the
Administration >X.509 Certificate/Key Management web page.
Vista de pagina 80
1 2 ... 76 77 78 79 80 81 82 83 84 85 86 ... 270 271

Comentarios a estos manuales

Sin comentarios