Linksys WAG325N manual Security VPN, Establishing a Tunnel, Remote Security Gateway

Page 20

Chapter 3

Advanced Configuration

Security > VPN

Security > VPN Tunnel

Establishing a Tunnel

The Gateway creates a tunnel or channel between two endpoints, so that the data or information between these endpoints is secure. To establish this tunnel, select the tunnel you wish to create in the Select Tunnel Entry drop- down box. It is possible to create up to two simultaneous tunnels. To delete a tunnel, click the Delete button. To view a summary of that tunnel, click the Summary button.

VPN Summary

Then check the box next to Enable to enable the tunnel.

Once the tunnel is enabled, enter the name of the tunnel in the Tunnel Name field. This is to allow you to identify multiple tunnels and does not have to match the name used at the other end of the tunnel.

Local Secure Group and Remote Secure Group

A Local Secure Group is a computer(s) on your network that can access the tunnel. A Remote Secure Group is a computer (s) on the remote end of the tunnel that can

access the tunnel. Under Local Secure Group, you may choose from Subnet and IP address. Under Remote Secure Group, you may choose from IP address, Subnet, and Any.

Subnet  If you select Subnet (which is also the default), this will allow all computers on the local subnet to access the tunnel. When using the Subnet setting, the default values of 0 should remain in the last fields of the IP and Mask settings.

IP Address  If you select IP Address, only the computer with the specific IP address that you enter will be able to access the tunnel.

Any  If you select Any for the Remote Security Group, the local VPN Router will accept a request from any IP address. This setting should be chosen when the other endpoint is using DHCP or PPPoE on the Internet side.

Remote Security Gateway

The Remote Security Gateway is the VPN device, such as a second VPN Router, on the remote end of the VPN tunnel. Under Remote Security Gateway, you have three options: IP address, FQDN, and Any. In this section, you can also set the levels and types of encryption and authentication.

IP Address  If you select IP Address, enter the IP address of the VPN device at the other end of the tunnel. The remote VPN device can be another VPN Router, a VPN Server, or a computer with VPN client software that supports IPSec. The IP address may either be static (permanent) or dynamic (changing), depending on the settings of the remote VPN device. Make sure that you have entered the IP address correctly, or the connection cannot be made. Remember, this is NOT the IP address of the local VPN Router, but the IP address of the remote VPN Router or device with which you wish to communicate.

FQDN (Fully Qualified Domain Name)  If you select FQDN, enter the FQDN of the VPN device at the other end of the tunnel. The remote VPN device can be another VPN Router, a VPN Server, or a computer with VPN client software that supports IPSec. The FQDN is the host name and domain name for a specific computer on the Internet, for example, vpn.myvpnserver.com.

Any  If you select Any for the Remote Security Gateway, the VPN device at the other end of the tunnel will accept a request from any IP address. The remote VPN device can be another VPN Router, a VPN Server, or a computer with VPN client software that supports IPSec. If the remote user has an unknown or dynamic IP address (such as a professional on the road or a telecommuter using DHCP or PPPoE), then Any should be selected.

Encryption  Usingencryptionhelpsmakeyourconnection more secure. The encryption type used must be the same type of encryption that is being used by the VPN device at the other end of the tunnel. You may choose not to encrypt by selecting Disable.

Wireless-N ADSL2+ Gateway

19

Image 20
Contents User Guide About This Guide Icon DescriptionsOnline Resources Copyright and TrademarksTable of Contents Wireless-N ADSL2+ Gateway Iii Back Panel Chapter Product OverviewLEDs Additional Security Tips Chapter Wireless Security ChecklistGeneral Network Security Guidelines Connection InstallationSetup Chapter Advanced Configuration How to Access the Web-Based UtilitySetup Basic Setup Internet SetupVC Settings PPPoA SettingsRFC 2364 PPPoA RFC 2516 PPPoEPPPoE Settings IP SettingsRFC 1483 Routed IPoANetwork Setup Bridge Mode OnlyOptional Settings Network Address Server Settings DhcpSetup Ddns Time SettingsDdns Service LanguageSetup MAC Address Clone Setup Advanced RoutingWireless Basic Wireless Settings Wireless NetworkAdvanced Routing Dynamic RoutingWireless Wireless Security Wireless SecurityWPA2-Personal Recommended WPA2-EnterpriseRadius May affect wireless performance. WPA2 recom- mended Wireless Wireless Mac Filter Wireless MAC FilterWEP May affect wireless performance. WPA2 recommend- ed Access RestrictionsWireless Advanced Wireless Settings Advanced WirelessSecurity Firewall Security VPN PassthroughRemote Security Gateway Security VPNEstablishing a Tunnel Advanced VPN Tunnel Setup Key ManagementSummary PhaseInternet Access Policy Applications and Gaming Single Port Forwarding Single Port ForwardingApplications and Gaming Port Range Forwarding Applications & Gaming Port Range TriggeringPort Range Forwarding Port Range TriggeringWireless Internet Access PriorityApplications and Gaming DMZ Applications and Gaming QoSApplications Add a New ApplicationOnline Games MAC AddressAdministration Management Gateway AccessLocal Gateway Access Remote Gateway AccessAdministration Log Administration DiagnosticsUPnP LogAdministration Backup & Restore Administration Factory DefaultsStatus Local Network Administration Firmware UpgradeStatus Gateway Status Wireless Status DSL ConnectionDhcp Server Dhcp Client TableDSL Connection PVC ConnectionAppendix a Troubleshooting Your computer cannot connect to the InternetAppendix B Specifications WAG325NAppendix C Warranty Information Safety Notices FCC StatementIndustry Canada Statement Avis d’Industrie CanadaПриложими Клаузи Bulgarian Denmark CE MarkingNational Restrictions Product Usage Restrictions Technical Documents onDansk Danish Miljøinformation for kunder i EU Regulatory Information Norsk Norwegian Miljøinformasjon for kunder i EU Regulatory Information